Compliance 11 min read

ISO Management System Revisions: What Changes by 2028

J

Jared Clark

September 09, 2026

Every certified organization eventually asks the same question at the worst possible time: is the standard I just spent two years implementing about to change underneath me? For ISO management system standards, the honest answer is that change is not an event. It's a schedule, written into ISO's own rulebook, and most certified organizations never look at it until an auditor mentions an amendment they haven't addressed.

Here's the mechanism. ISO/IEC Directives, Part 1 requires every International Standard to go through systematic review at intervals of, at most, five years. A technical committee votes to confirm the standard as-is, revise it, or withdraw it. Confirmation is common — ISO 9001:2015 was confirmed without change in 2021, for instance — but confirmation doesn't mean nothing happens between full revisions. Amendments, corrigenda, and structural updates to the common framework all move independently of the headline "20XX" date on the cover page. That's the part most quality managers miss, and it's the part that actually shows up on your next audit.

The Climate Change Amendment You May Have Already Missed

In February 2024, ISO published Amendment 1 to a set of management system standards built on the Harmonized Structure, including ISO 9001:2015, ISO 14001:2015, and ISO 45001:2018. The amendment is narrow but real: it adds a requirement, in clauses 4.1 and 4.2, that organizations determine whether climate change is a relevant issue for their management system and whether it affects the needs and expectations of interested parties. It does not require a carbon footprint calculation or an environmental target. It requires you to document that you considered the question.

Per the IAF/ISO Joint Communiqué on the addition of Climate Change considerations to management system standards, published 22 February 2024, the amendment took effect immediately on publication — 23 February 2024, with no transition period — and certification bodies were directed to begin confirming conformity at an organization's next scheduled audit activity: Stage 1, Stage 2, surveillance, or recertification. If your last audit fell after that date and your context analysis in clause 4.1 doesn't mention climate change, that's a finding waiting to be written. I've seen organizations treat this as a footnote. It isn't. It's a live amendment with a live enforcement date, and it's the single most common gap I see in management review records right now.

Why This Round of Revisions Looks Different

Past ISO revision cycles moved one standard at a time. ISO 9001 revised in 2000, 2008, and 2015; ISO 14001 followed its own separate rhythm. What's different now is that ISO's Harmonized Structure — the common skeleton of clauses 4 through 10 shared across QMS, EMS, OH&S, and information security standards — was itself updated in the 2024 edition of the ISO/IEC Directives, Part 1 Consolidated ISO Supplement. Annex SL, the document that used to define this shared architecture, had already been formally renamed the Harmonized Structure in an earlier edition of the Directives, and the climate change clause is one of the first substantive changes to move through that renamed structure via the 2024 update.

That matters because it means future changes to the common clauses will likely propagate across multiple standards at once, the way the climate change amendment did. If you hold ISO 9001, ISO 14001, and ISO 45001 together, as a lot of manufacturers and food processors do, you're not tracking three independent revision schedules anymore. You're tracking one shared structure plus whatever each technical committee layers on top of it.

Standard-by-Standard: Where Each One Sits

Standard Current Edition Owning Committee Recent Amendment Where It Stands
ISO 9001 (Quality) 2015 ISO/TC 176/SC 2 Amd 1:2024 (climate change) Confirmed 2021; base text unchanged, amendment in force
ISO 14001 (Environmental) 2015 ISO/TC 207/SC 1 Amd 1:2024 (climate change) Past its nominal five-year window; committee discussion on a fuller revision is active
ISO 45001 (Occupational Health & Safety) 2018 ISO/PC 283 Amd 1:2024 (climate change) Younger standard; amendment applied, no full revision announced
ISO/IEC 27001 (Information Security) 2022 ISO/IEC JTC 1/SC 27 None yet Newest major revision in this group; next systematic review due around 2027
ISO 22000 (Food Safety) 2018 ISO/TC 34/SC 17 None yet Approaching its five-year systematic review window
ISO 13485 (Medical Devices QMS) 2016 ISO/TC 210 None yet Confirmed in its most recent systematic review without amendment
ISO 42001 (AI Management) 2023 ISO/IEC JTC 1/SC 42 None yet New standard; first systematic review not due until roughly 2028

A word on how to read that table: "no full revision announced" is not the same as "safe until further notice." ISO 14001 is the standard most clearly overdue for a real look, not just an amendment, and organizations that certify to it should expect committee-level movement before 2028 rather than a stable status quo.

ISO 9001: Confirmed, Not Frozen

ISO 9001:2015 was confirmed as-is by ISO/TC 176/SC 2 in its most recent systematic review, which means the base standard's ten clauses are not being rewritten. But "confirmed" only applies to the core text. The climate change amendment still applies to every ISO 9001 certificate holder, and TC 176 has been vocal in public forums about wanting the next full revision, whenever it comes, to address risk-based thinking around supply chain resilience more directly. Nothing there is locked in yet. What is locked in is clause 4.1's climate change language, which auditors are now checking as a matter of course.

ISO 14001: The One Most Likely to Move First

ISO 14001:2015 is the standard I'd watch most closely through 2027. It's the oldest of the group still without a confirmed next-revision date, and its five-year systematic review window closed years ago. TC 207 has been openly discussing how environmental management should account for both climate mitigation and adaptation, not just the interested-party language the 2024 amendment added. If a full revision lands before 2028, ISO 14001 is the leading candidate. Organizations recertifying against it in the next two years should build in slack for a transition period rather than assuming the 2015 text is the last word.

ISO 45001 and the Amendment-Only Pattern

ISO 45001:2018 is newer, and it shows: the committee's position through the current cycle has been to apply the same climate change amendment as ISO 9001 and ISO 14001 without opening the door to a broader rewrite. That's the pattern worth naming, because it tells you something about how ISO is handling this generation of common-clause updates: mature standards get the amendment bolted on, and a fuller revision waits for the standard's own natural review point. For ISO 45001, that point isn't imminent.

ISO/IEC 27001: Freshly Revised, Watch the Controls Annex

ISO/IEC 27001:2022 is the newest major revision on this list, and its Annex A control set already reflects the 2022 update to ISO/IEC 27002. Because it's the newest, it's also the standard least likely to see a full revision before 2028 — systematic review five-year clocks run from publication, which puts 27001's next formal checkpoint around 2027. What's more likely in the interim is guidance-document movement: ISO/IEC 27002 and the sector-specific extensions (27017, 27018, 27701) tend to update faster than the parent standard, and those changes ripple into your Statement of Applicability even when 27001 itself hasn't moved.

ISO 22000 and ISO 13485: Quiet, But Due

ISO 22000:2018 is edging toward its own systematic review window, and food safety certificate holders should expect TC 34 to signal direction sometime in the next cycle, even if a published revision doesn't land until closer to 2028. ISO 13485:2016 has been confirmed in its most recent systematic review without a full rewrite, which is unusual longevity for a standard tied to a regulatory landscape (EU MDR, FDA QSR) that has itself changed substantially since 2016. In my view, that gap between a static standard and a moving regulatory backdrop is exactly the kind of pressure that eventually forces a technical committee's hand, whether or not 2028 is the year it happens.

ISO 42001: Too New to Revise, Too Important to Ignore

ISO 42001:2023, the AI management system standard, is the outlier here simply because it's brand new. Its first systematic review isn't due until roughly five years after publication, putting it right at the edge of this article's 2028 horizon. The standard everyone should actually watch is the same Harmonized Structure discussion driving the climate change amendment: as ISO's common clauses evolve, a young standard like 42001, built on that same skeleton, inherits those changes fastest.

What This Means for Your Certification Timeline

None of this should change what you do this quarter. It should change what you build into your management review cycle for the next eighteen months. Three things I'd tell any certified organization right now:

  • Confirm your documentation. Your clause 4.1 and 4.2 documentation should actually name climate change as a considered issue, even if the conclusion is "not currently material to our context." A documented conclusion is defensible. A silent gap is a nonconformity.
  • Don't treat ISO 14001:2015 as a permanent baseline. If you hold ISO 14001, build your next internal audit cycle assuming a transition period could open before your next recertification, and watch ISO/TC 207 announcements rather than waiting for your certification body to tell you.
  • Treat amendments as their own audit trigger, separate from full revisions. Certification bodies are required to verify amendment conformity at the next scheduled audit after the amendment's enforcement date, not at your convenience. That's already happened for the 2024 climate change amendment. It will happen again for whatever comes out of the Harmonized Structure discussion next.

A management system that only reacts to full revisions is always one amendment behind. The organizations that stay ahead of this build the systematic review calendar into their own internal audit schedule instead of waiting for a nonconformity to surface it.

If you're recertifying against any of these standards in the next twelve months, or building out a new management system from scratch, it's worth having someone map the current amendment status against your existing documentation before your next audit window opens. That's a fast gap check, not a redesign, and it's the kind of thing worth getting right before an auditor finds it for you. Certify Consulting works through exactly this kind of standards mapping for clients preparing for ISO 9001 certification and ISO 14001 certification, among others.

Frequently Asked Questions

Does the 2024 climate change amendment require a carbon footprint or emissions target? No. Amendment 1:2024 to ISO 9001:2015, ISO 14001:2015, and ISO 45001:2018 only requires that clauses 4.1 and 4.2 document whether climate change is a relevant issue for the organization's context and interested parties. It does not mandate measurement, targets, or reduction commitments.

When will certification bodies start checking for the climate change amendment? Per the IAF/ISO Joint Communiqué (published 22 February 2024), the amendment took effect immediately on publication — 23 February 2024, with no transition period — and certification bodies were directed to verify conformity at an organization's next scheduled audit activity, including surveillance audits already in progress.

Is ISO 9001:2015 getting a full revision before 2028? Not based on current committee action. ISO/TC 176/SC 2 confirmed ISO 9001:2015 without change in its most recent systematic review. The amendment applies, but the base ten clauses are unchanged for now.

Which ISO management system standard is most likely to see a full revision first? ISO 14001:2015 is the strongest candidate. It's past its nominal five-year systematic review window, and ISO/TC 207 has been discussing broader environmental management changes beyond the 2024 amendment.

Does ISO/IEC 27001:2022 need updating for AI-related risks? Not imminently — ISO/IEC JTC 1/SC 27 hasn't signaled an AI-specific amendment in development, and 27001's next scheduled systematic review isn't due until around 2027. Organizations managing AI risk alongside information security typically pair ISO/IEC 27001 with ISO/IEC 42001 rather than waiting on a 27001 revision.

What should we do right now if we're not sure our documentation covers the amendment? Pull your clause 4.1 context analysis and clause 4.2 interested-party register and confirm climate change is addressed, even briefly. If it's silent, that's the fastest fix available before your next audit.

Last updated: 2026-09-09

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.