Skip links

The ISO Standards Family

They share a structure

Most modern ISO management standards are built the same way.

Same section structure. Same core requirements — context, leadership, planning, support, operation, evaluation, improvement. Same underlying ideas of PDCA and risk-based thinking.

Which has a practical consequence: if you have one, adding another is far less work than the first. The management review, the internal audit programme, the document control, the corrective action process — those are shared.

You are adding requirements, not building a second system.

The main ones

ISO 9001 — Quality

The foundation. Consistent output, meeting customer requirements, continual improvement.

Applies to anyone. Manufacturing, services, software, healthcare. The most widely held certification of any of these.

Start here if you are starting at all.

ISO 14001 — Environment

Managing environmental impact. Identifying what you affect, complying with environmental law, reducing impact over time.

Who needs it: anyone with a meaningful physical footprint, and increasingly anyone tendering for public contracts or supplying larger companies with environmental commitments of their own.

ISO 45001 — Occupational Health and Safety

Managing workplace health and safety risk. Hazard identification, worker participation, incident investigation.

Who needs it: construction, manufacturing, anywhere with real physical risk. Often required to work on client sites.

Worker participation is a genuine requirement here, not a formality — auditors check that workers were actually consulted.

ISO 27001 — Information Security

Managing information security risk. Access control, incident response, and a documented set of controls.

Who needs it: anyone handling client data. Increasingly required by enterprise customers before they will contract with a supplier.

The one growing fastest in software and services.

FIGURE 1: THE FOUR MOST COMMON

ISO 9001 — Quality

  • The foundation. Applies to anyone. Start here.

ISO 27001 — Information Security

  • Growing fastest. Enterprise customers increasingly require it.

ISO 45001 — Health and Safety

  • Physical risk. Often needed to work on client sites.

ISO 14001 — Environment

  • Environmental impact. Common in public tendering.

ISO 13485 — Medical Devices

Quality management for medical devices. Based on 9001 but stricter, with much heavier requirements on documentation, traceability and risk.

Who needs it: anyone making, sterilising, distributing or servicing medical devices. Effectively mandatory for market access in most jurisdictions.

Note: it is deliberately less focused on continual improvement than 9001 and more on consistent regulatory compliance. Different priority, and that is intentional.

ISO 50001 — Energy

Managing energy performance. Measuring use, setting objectives, improving efficiency.

Who needs it: energy-intensive operations. In some countries it brings tax or regulatory advantages, which is often the actual reason for adopting it.

The sector-specific ones

Built on ISO 9001, with substantial additional requirements.

IATF 16949 — Automotive

For the automotive supply chain. Built on 9001, with much more on defect prevention, variation reduction, and supply chain control.

Substantially harder than 9001. More prescriptive, more tooling required — FMEA, SPC, MSA, control plans — and audited more rigorously.

Effectively mandatory to supply automotive manufacturers.

AS9100D — Aerospace

For aerospace, space and defence. Also built on 9001, with additions on configuration management, counterfeit part prevention, product safety and risk.

Also effectively mandatory for that supply chain.

FIGURE 2: GENERAL VERSUS SECTOR STANDARDS

ISO 9001

  • Applies to any organisation
  • You decide how to meet requirements
  • Focus on continual improvement
  • The usual starting point

IATF 16949 / AS9100D

  • Specific supply chains
  • More prescriptive on method
  • Required tools — FMEA, SPC, MSA
  • Audited more rigorously

Running more than one

Common, and much easier than running two separate systems.

What gets shared:

Document control. Internal audit programme. Management review. Corrective action process. Competence and training records. Supplier control.

What stays separate:

The specific risks. The specific legal requirements. The specific objectives and measures.

Practically: one management review covering quality, environment and safety. One internal audit visit assessing against all three. One corrective action system.

This is called an integrated management system, and it is how most multi-certified organisations operate. Certification bodies audit them together, which also reduces cost.

Choosing what you need

Three questions.

What do customers require? Look at recent tenders and contracts. This is usually the deciding factor.

What does regulation require? Medical devices and some sectors have no choice.

What risk do you actually carry? If your main exposure is information security, 27001 helps more than 14001 — regardless of which is easier.

A common sequence: ISO 9001 first, because it is the foundation and shares structure with everything else. Then whichever the market or the risk demands.

The exception: if a specific customer requires 27001 or 45001 now, start there. The certificate you need beats the one that would have been a tidier starting point.

What they have in common

All of them ask the same underlying things, which is why the second is easier than the first.

Know your context and your risks.

Involve leadership genuinely.

Control your processes.

Audit yourself and find things.

Handle nonconformities at the root cause.

Review, at management level, and act.

If those are working, most of any standard is already in place. The rest is the specific subject matter.

FIGURE 3: A SENSIBLE ORDER

ISO 9001 first

  • The foundation, shared structure with the rest

Then what the market needs

  • 27001, 45001, 14001 — whichever is asked for

Sector standards if required

  • IATF or AS9100 for those supply chains

Integrate, do not duplicate

  • One review, one audit programme, one CAPA process

The short version

ISO 9001 is the foundation, and most other management standards share its structure — which makes the second certification far cheaper than the first.

27001 is the fastest growing in services, driven by enterprise customers requiring it.

13485, IATF 16949 and AS9100D are sector requirements rather than choices, in their industries.

Run them as one integrated system, not several. Shared audits, shared review, shared corrective action — that is where the saving is.

Adding a second standard to an existing system?

Get in touch. Most of the work is already done if your first system is genuine — the saving comes from integrating rather than duplicating.

Leave a comment

Drag