The ISO Standards Family
They share a structure
Most modern ISO management standards are built the same way.
Same section structure. Same core requirements — context, leadership, planning, support, operation, evaluation, improvement. Same underlying ideas of PDCA and risk-based thinking.
Which has a practical consequence: if you have one, adding another is far less work than the first. The management review, the internal audit programme, the document control, the corrective action process — those are shared.
You are adding requirements, not building a second system.
The main ones
ISO 9001 — Quality
The foundation. Consistent output, meeting customer requirements, continual improvement.
Applies to anyone. Manufacturing, services, software, healthcare. The most widely held certification of any of these.
Start here if you are starting at all.
ISO 14001 — Environment
Managing environmental impact. Identifying what you affect, complying with environmental law, reducing impact over time.
Who needs it: anyone with a meaningful physical footprint, and increasingly anyone tendering for public contracts or supplying larger companies with environmental commitments of their own.
ISO 45001 — Occupational Health and Safety
Managing workplace health and safety risk. Hazard identification, worker participation, incident investigation.
Who needs it: construction, manufacturing, anywhere with real physical risk. Often required to work on client sites.
Worker participation is a genuine requirement here, not a formality — auditors check that workers were actually consulted.
ISO 27001 — Information Security
Managing information security risk. Access control, incident response, and a documented set of controls.
Who needs it: anyone handling client data. Increasingly required by enterprise customers before they will contract with a supplier.
The one growing fastest in software and services.
FIGURE 1: THE FOUR MOST COMMON
ISO 9001 — Quality
- The foundation. Applies to anyone. Start here.
ISO 27001 — Information Security
- Growing fastest. Enterprise customers increasingly require it.
ISO 45001 — Health and Safety
- Physical risk. Often needed to work on client sites.
ISO 14001 — Environment
- Environmental impact. Common in public tendering.
ISO 13485 — Medical Devices
Quality management for medical devices. Based on 9001 but stricter, with much heavier requirements on documentation, traceability and risk.
Who needs it: anyone making, sterilising, distributing or servicing medical devices. Effectively mandatory for market access in most jurisdictions.
Note: it is deliberately less focused on continual improvement than 9001 and more on consistent regulatory compliance. Different priority, and that is intentional.
ISO 50001 — Energy
Managing energy performance. Measuring use, setting objectives, improving efficiency.
Who needs it: energy-intensive operations. In some countries it brings tax or regulatory advantages, which is often the actual reason for adopting it.
The sector-specific ones
Built on ISO 9001, with substantial additional requirements.
IATF 16949 — Automotive
For the automotive supply chain. Built on 9001, with much more on defect prevention, variation reduction, and supply chain control.
Substantially harder than 9001. More prescriptive, more tooling required — FMEA, SPC, MSA, control plans — and audited more rigorously.
Effectively mandatory to supply automotive manufacturers.
AS9100D — Aerospace
For aerospace, space and defence. Also built on 9001, with additions on configuration management, counterfeit part prevention, product safety and risk.
Also effectively mandatory for that supply chain.
FIGURE 2: GENERAL VERSUS SECTOR STANDARDS
ISO 9001
- Applies to any organisation
- You decide how to meet requirements
- Focus on continual improvement
- The usual starting point
IATF 16949 / AS9100D
- Specific supply chains
- More prescriptive on method
- Required tools — FMEA, SPC, MSA
- Audited more rigorously
Running more than one
Common, and much easier than running two separate systems.
What gets shared:
Document control. Internal audit programme. Management review. Corrective action process. Competence and training records. Supplier control.
What stays separate:
The specific risks. The specific legal requirements. The specific objectives and measures.
Practically: one management review covering quality, environment and safety. One internal audit visit assessing against all three. One corrective action system.
This is called an integrated management system, and it is how most multi-certified organisations operate. Certification bodies audit them together, which also reduces cost.
Choosing what you need
Three questions.
What do customers require? Look at recent tenders and contracts. This is usually the deciding factor.
What does regulation require? Medical devices and some sectors have no choice.
What risk do you actually carry? If your main exposure is information security, 27001 helps more than 14001 — regardless of which is easier.
A common sequence: ISO 9001 first, because it is the foundation and shares structure with everything else. Then whichever the market or the risk demands.
The exception: if a specific customer requires 27001 or 45001 now, start there. The certificate you need beats the one that would have been a tidier starting point.
What they have in common
All of them ask the same underlying things, which is why the second is easier than the first.
Know your context and your risks.
Involve leadership genuinely.
Control your processes.
Audit yourself and find things.
Handle nonconformities at the root cause.
Review, at management level, and act.
If those are working, most of any standard is already in place. The rest is the specific subject matter.
FIGURE 3: A SENSIBLE ORDER
ISO 9001 first
- The foundation, shared structure with the rest
Then what the market needs
- 27001, 45001, 14001 — whichever is asked for
Sector standards if required
- IATF or AS9100 for those supply chains
Integrate, do not duplicate
- One review, one audit programme, one CAPA process
The short version
ISO 9001 is the foundation, and most other management standards share its structure — which makes the second certification far cheaper than the first.
27001 is the fastest growing in services, driven by enterprise customers requiring it.
13485, IATF 16949 and AS9100D are sector requirements rather than choices, in their industries.
Run them as one integrated system, not several. Shared audits, shared review, shared corrective action — that is where the saving is.
Adding a second standard to an existing system?
Get in touch. Most of the work is already done if your first system is genuine — the saving comes from integrating rather than duplicating.