Is ANSI Webstore Legit? A Buyer’s Guide (2026)

Before paying $150–$400 for a standard, buyers want to know if ANSI Webstore is legitimate. This guide covers who runs it, how it compares to resellers and free PDFs, and — the part most buyers miss — how to confirm you’re buying the correct edition.

What to know before you enter your card number for an ISO, ASTM, or ANSI standard

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


You Searched “Is ANSI Webstore Legit” for a Reason

You’re not being paranoid. You found a webpage that wants $150–$400 for a PDF, the checkout page looks a little dated, and you’ve probably seen at least one sketchy standards-reseller site pop up in the same search results. Before you hand over a company card for a document your auditor is going to check line by line, you want to know exactly who you’re paying.

Here’s the short answer: ANSI Webstore is legit — it’s the official online store operated by the American National Standards Institute, the U.S. nonprofit that has coordinated the voluntary standards and conformity assessment system for more than a century.

Is ANSI Webstore Legit? Yes. The ANSI Webstore is ANSI’s official online standards ordering platform, selling standards from more than 150 publishers with individual purchases, discounted packages, and multi-user access options.

But here’s the distinction that actually matters: a legitimate source doesn’t automatically mean the correct edition for your application. ANSI sells historical and superseded editions right alongside current ones — so “legit” and “the exact document your certification requires” are two different questions, and this guide covers both.

From the Floor: I’ve seen an operations team walk into a surveillance audit with a printed copy of a standard that was two editions behind — pulled from a PDF a supplier had forwarded around years earlier. The auditor caught it in the first ten minutes, and the finding wasn’t about the process. It was about the document. That’s the actual risk with standards purchases: not getting scammed out of your money, but building your QMS around the wrong edition — a risk that exists even when you buy from the right source.

Before you buy anything, make sure you know exactly which clauses and documentation your certification actually requires — not just which standard number to search for.

👉 Get the free ISO 9001 Roadmap — a step-by-step breakdown of what your QMS needs before you spend a dollar on documents or consultants.

In This Guide:

  • What the ANSI Webstore actually is, and who’s behind it
  • Official store vs. resellers vs. “free” PDFs — what changes at each level
  • Payment, delivery, and what you get for your money
  • Why “legitimate source” and “correct edition” aren’t the same thing
  • A pre-purchase checklist so you buy the right edition the first time


👉 Start Here (Top Resources)

If you’re ready to buy, these are the fastest paths:


What Is the ANSI Webstore, Actually?

The ANSI Webstore (webstore.ansi.org) is the official electronic ordering platform run by the American National Standards Institute, a private nonprofit founded in 1918. ANSI doesn’t write most of the standards it sells — it accredits the procedures of the organizations that do, and it’s the official U.S. representative to the International Organization for Standardization.

That’s an important distinction, not just a technicality. When you purchase ISO 9001, ISO 14001, or a SAE aerospace standard through the webstore, you’re buying an authorized, officially published edition sold with the standards developer’s authorization — not a scanned copy, not a summary, and not a document of unknown origin. What it doesn’t automatically tell you is whether the specific edition you selected is the one currently required by your certification, contract, or customer — more on that below.

The platform itself covers a lot of ground: standards from more than 150 publishers, delivered mostly as PDF, with a handful still available in print. If you’re comparing document costs before you commit, Why Are ISO Standards So Expensive? breaks down where that price actually goes.


Is ANSI Webstore Legit, or Is There a Catch?

ANSI Webstore legit comparison showing official standards source, third-party reseller, and unverified free PDF copy
ANSI Webstore legit? Compare an official standards source with third-party resellers and unverified free PDF copies before buying.

There’s no catch — but there is a pattern worth understanding. “Legit” gets confused with “cheap” a lot in this space, and the two aren’t related.

The stronger evidence is simpler than any third-party rating tool: webstore.ansi.org is operated by ANSI itself. ANSI identifies the Webstore as its own electronic standards ordering and delivery system, listing standards from more than 150 publishers. That doesn’t mean every document on the Webstore is automatically the right document for your application — it means you’re dealing with the official ANSI storefront rather than an anonymous third-party reseller.

Where things get murkier is one step removed from ANSI itself:

  • Reseller sites that mark up standards and sometimes sell outdated editions without disclosing it
  • “Free download” sites that host pirated copies, often years out of date, with no guarantee the text matches what your registrar will audit against
  • Marketplace listings on general e-commerce platforms, where you genuinely cannot verify which edition you’re getting until it arrives

None of those are “ANSI Webstore” problems. They’re what happens when buyers go looking for a shortcut around the official source. For a deeper look at what’s legal and what isn’t when it comes to standards distribution, see Legal Download ANSI Standards.

Official Source vs. Reseller vs. “Free” PDF

SourceEdition GuaranteeLegal StandingTypical Price
ANSI WebstoreAuthorized edition selected at checkout — confirm year/status yourselfFully licensedFull retail (packages/coupon reduce cost)
Third-party resellerNot guaranteed — often outdatedVaries; some unauthorized resaleUsually similar or higher
“Free” PDF / forwarded copyFrequently outdated or alteredCopyright infringement$0 — but audit risk

If you’re weighing digital against a printed copy once you’ve settled on the official source, Digital vs. Printed ISO Standards walks through that decision.


Is It Safe to Enter Your Payment Info?

The ANSI Webstore accepts major credit cards and deposit accounts, and ANSI’s own FAQ confirms that completed orders generate an email confirmation with order details. As with any online purchase, use the official webstore.ansi.org domain and verify the checkout page before entering payment information.

On invoicing: ANSI does not send invoices for Webstore orders. After checkout, you receive an email confirmation containing your order details — save that confirmation for your procurement records. If your accounting team needs a deposit account set up for repeat purchases, that’s a standard request the webstore supports for organizations that buy standards regularly.

If you’re under time pressure before an audit → don’t wait on a mailed print copy. Buy the digital PDF edition and confirm it’s the current one before your surveillance or certification audit date, not after.


What You Actually Get When You Buy

ANSI Webstore legit guide showing what to do after buying a standards PDF, including download, license verification, and record retention
ANSI Webstore legit buying guide showing the steps after checkout: save the confirmation, download the PDF, verify licensing, and retain procurement records.

Most purchases are delivered as a downloadable PDF, licensed for the number of users specified at checkout — usually single-user unless you buy a multi-user or site license. That licensing detail matters more than people expect: sharing a single-user PDF across a whole quality team generally isn’t permitted under the license, not just a courtesy the vendor overlooks.

One detail worth knowing before you buy: for individual standards, the download link is active for seven days after purchase. Download and save your copy promptly rather than planning to come back for it later — a link you let lapse means contacting customer service to reissue it.

For standards you’ll reference constantly — ISO 9001, your industry-specific standard, anything your team pulls up during internal audits — compare the package price against buying each one individually before you check out. ANSI offers discounted standards packages for many collections, and if you’re building out a management system that touches more than one standard, that comparison is worth ten minutes of your time.

👉 Not sure your team is even buying against current requirements? Grab the Manufacturing Compliance Checklist before you spend another dollar on documentation you might not need yet.


Common Objection: “Why Not Just Find It Free?”

This is the honest objection, so let’s address it directly. Standards are expensive, and it’s tempting to search around for a copy someone else already paid for.

The problem isn’t getting caught — it’s getting it wrong. Standards get revised. ISO 14001 moved from the 2015 edition to a 2026 edition. AS9100 has moved through multiple revisions. A “free” copy circulating online has no mechanism to tell you it’s stale, and your registrar’s auditor isn’t going to accept “I didn’t know there was a newer edition” as an answer during a nonconformance discussion.

Buying through the ANSI Webstore gives you an authorized source for the standard you select — but it doesn’t automatically hand you the edition your certification or contract requires. That’s why checking the standard number, edition year, and revision status before checkout still matters, even when you’re buying from the official source.

ANSI Webstore legit guide showing how to verify the correct ISO standard edition, year, status, and certification requirements
ANSI Webstore legit? Verify the standard number, edition year, status, and applicable certification or contract requirements before purchasing.

Buyer’s Checklist Before You Purchase

✅ Confirm you’re on webstore.ansi.org — not a similarly-named domain
✅ Search by the exact standard number and confirm the edition year before adding to cart
✅ Filter for “Most Recent” rather than “Historical” unless you specifically need a superseded edition
✅ Check whether a package covers multiple standards you need — compare package price to individual pricing
✅ Apply code CC2026 at checkout for 5% off (valid through December 31, 2026)
✅ Confirm single-user vs. multi-user licensing matches how many people need access
✅ Download your file within 7 days of purchase and save it to your records
✅ Save your email order confirmation for procurement or audit records

⚠️ If a price looks unusually low, verify the seller before buying — it’s likely a reseller or an outdated copy, not the official source


FAQ

Is the ANSI Webstore operated by ANSI?

Yes. The ANSI Webstore is ANSI’s official online standards ordering platform, rather than a licensed third-party reseller.

Is webstore.ansi.org safe to use?

It’s ANSI’s own official ordering platform, not a third-party site. The domain is operated directly by the American National Standards Institute.

Does ANSI Webstore sell outdated or superseded standards?

Yes — historical and withdrawn editions remain available alongside current ones, since some states and contracts still reference older versions. Always check whether a listing is marked “Most Recent” or “Historical” before buying, and confirm the edition your certification or contract actually requires.

Can I legally get ISO or ANSI standards for free?

Some standards referenced in public regulations are available for free reading (not download) through official reading-room programs. Outside of that narrow case, standards are copyrighted works, and free downloads circulating online are typically unauthorized copies of uncertain edition.

Why does the ANSI Webstore cost more than some other sites I’ve found?

Other sites are usually reselling at a markup or distributing outdated copies without disclosing it. The webstore price reflects an authorized, officially published edition — not a discount copy of unknown accuracy.

Does ANSI Webstore ship or sell internationally?

Yes. The webstore serves international buyers and lists standards from ISO, IEC, and other international bodies alongside U.S. standards, which is useful if your operation buys against both domestic and international requirements.

What file format will I receive, and how long do I have to download it?

Most purchases are delivered as a licensed PDF, downloadable immediately after checkout. The download link stays active for seven days, so download and save your copy promptly.

Is there a discount code for ANSI Webstore?

Yes — code CC2026 takes 5% off qualifying purchases through December 31, 2026.

I need the same standard for multiple team members. What do I buy?

Check the licensing option at checkout. Single-user licenses are for one person; if more than one person on your team needs direct access to the document, you’ll need a multi-user or site license rather than sharing a single-user PDF.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system, so you know what you’re actually buying documents for.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

Not Sure What to Do Next?

🔹 Still researching? Read Where to Buy ISO Standards for the full landscape of official sources before you commit to a purchase.

🔹 Ready to buy your standard? Head to the ANSI Webstore and search by standard number and edition year — apply code CC2026 at checkout for 5% off.

🔹 Buying more than one standard? Compare individual pricing against the ANSI Webstore package option before you check out — for related standards, packages are often the better value, but check the numbers for your specific documents.

Buying the right document, from the right source, in the right edition, is the least glamorous part of getting certified — and the part that quietly causes the most audit headaches when it’s skipped. The Standards Navigator exists to make that decision boring and correct, not expensive and uncertain.


Before You Go

Buying the wrong edition, or buying from the wrong source, doesn’t usually surface until an auditor is standing in front of you asking why your documented procedure doesn’t match current clause numbers. Manufacturers who get this right treat the standard itself as step one — not an afterthought after the QMS is already built. Manufacturers who get it wrong find out during a nonconformance write-up, when it’s expensive to fix.

The Standards Navigator covers where to legally and confidently source every standard your certification actually requires — not just ISO 9001, but the full range of clusters manufacturers deal with.

👉 Get updates on standards purchasing and document sourcing
👉 Be first to access new compliance checklists and gap assessment tools

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO 14001:2026 Clauses Explained: A Complete Clause-by-Clause Breakdown

ISO 14001:2026 replaces the 2015 edition, but most of the standard is unchanged. This guide breaks down every clause — the five named environmental conditions in 4.1, the strengthened scope requirements in 4.3, the new Clause 6.3 on change management, the restructured audit and management-review requirements in Clause 9, and the 10.1/10.3 merge — so manufacturers know exactly what needs updating before their certification body’s April 30, 2029 transition deadline.

What Changed in Every Clause — And What Your EMS Actually Needs to Do About It

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your EMS Isn’t Broken. But Several Clauses Just Changed Underneath It.

This ISO 14001:2026 clauses explained guide breaks down every clause so you know exactly what changed and what to leave alone.

If you’re certified to ISO 14001:2015, here’s the uncomfortable truth: your certificate has an expiration date now, and it’s not the one on the wall.

ISO 14001:2026 was published April 15, 2026. It cancels and replaces the 2015 edition. Every organization holding an ISO 14001:2015 certificate now has until April 30, 2029 — confirmed directly in UKAS’s published technical bulletin for accredited certification bodies — to move to the new edition or lose certified status entirely.

The good news: this is not a rebuild. The Plan-Do-Check-Act structure is untouched. The ten-clause Harmonized Structure you already know from ISO 9001 and ISO 45001 is still there. What changed is narrower and more specific than most transition guides make it sound — and that’s exactly why a clause-by-clause read matters more than a high-level summary. You need to know which clauses to touch and which ones to leave alone.

I’ve spent 25+ years in heavy industrial operations, and I hold ISO 9001 Internal Auditor certification and a Six Sigma Green Belt — which means I’ve been the one standing in front of an auditor when a clause got reinterpreted mid-cycle. When ISO 9001:2015 rolled out its own risk-based thinking language, I watched two “equivalent” fabrication shops get very different audit outcomes — one had mapped the new requirement into an existing procedure six months ahead, the other tried to bolt it on during the transition audit itself. The shops that treat a standard revision as a documentation exercise get surprised. The ones that treat it as a system update don’t.

EMS teams generally fall into one of two postures over the transition window: reactive gap-closing right before a transition audit, or a planned, clause-mapped update that folds into a normal surveillance cycle. Before your next audit window closes, run a structured gap check against the 2026 requirements

Get the Manufacturing Compliance Checklist — a practical reference for closing gaps before an auditor finds them for you.


In This Guide

  • What actually changed between ISO 14001:2015 and ISO 14001:2026, clause by clause
  • The one genuinely new clause (6.3) and why it exists
  • Which requirements are genuinely new, which are reorganized, and which are primarily clarified
  • How the 2024 Climate Change Amendment folds into the 2026 edition
  • Transition timeline and what your certification body will expect
  • Where to buy the standard and where to get training
  • A quick-reference audit checklist for your next internal audit


ISO 14001:2026 Clauses Explained: Quick Answer

ClauseWhat ChangedAction Needed
4.1Five named environmental conditions: climate change, biodiversity, pollution, resource availability, ecosystem healthUpdate context analysis
4.3Life-cycle perspective now required at the EMS scoping stageExtend scope justification upstream/downstream
6.1.4New sub-clause dedicated to risks and opportunitiesMake risks/opportunities traceable — register optional
6.3Entirely new clause — Planning of ChangesBuild or extend a change-management procedure
8.1“Externally provided processes, products and services” replaces “outsourced processes”Broaden supplier and flow-down controls
9.2.2Audit objectives now required for every internal auditAdd defined objectives to your audit programme
9.3Restructured into 9.3.1 / 9.3.2 / 9.3.3Update management review agenda and minutes template
10.1Merged with former 10.3 (Continual improvement)Update internal cross-references

👉 Start Here (Top Resources)


Why This Revision Happened

ISO doesn’t revise a management system standard every few years for the sake of it. ISO 14001:2015 has been in place over a decade, and in that time three things happened that the standard didn’t fully account for: climate reporting became a business expectation rather than a voluntary add-on, supply chain environmental accountability moved from “nice to have” to contractual requirement in many industries, and the 2024 Climate Change Amendment (Amendment 1) was issued as a stopgap that needed to be formally folded into the core text rather than living as a bolt-on.

ISO.org confirms the core structure of ISO 14001 remains the internationally recognized environmental management system framework it has always been — this revision sharpens the requirements, it doesn’t replace the model.

If you are already ISO 9001 or ISO 45001 certified → you’ll recognize most of what changed here immediately, because the 2026 revision closes gaps that made ISO 14001 feel slightly out of step with its Harmonized Structure siblings. Clause 6.3 is the clearest example — ISO 9001 has had it since 2015.


Clause 4: Context of the Organization

This is where the most-cited substantive change sits, spread across three sub-clauses.

Clause 4.1 (Understanding the organization and its context) now names five specific environmental conditions that organizations must explicitly consider: climate change, biodiversity, pollution levels, natural resource availability, and ecosystem health. Under the 2015 edition, these lived as Annex A examples rather than requirement text. The 2026 edition writes them into the “shall” statement itself — auditors will expect to see these named factors addressed in your context analysis, not filed under a generic catch-all.

Clause 4.2 (Understanding the needs and expectations of interested parties) carries the same tightening, with a new note clarifying the types of interested parties in language that aligns more closely with ISO 9001. If your organization already addressed the 2024 Climate Change Amendment, you’re largely ahead of this change — it’s been formally absorbed into the core text rather than treated as a standalone add-on.

Clause 4.3 (Determining the scope of the EMS) picks up a genuine substantive change of its own: the life-cycle perspective is now explicitly required at the scoping stage, not just when identifying environmental aspects later in Clause 6. In practice, this means your scope statement needs to reflect where you have control or influence across upstream and downstream activities — not just what happens inside your fence line. A manufacturing site that already controls emissions and waste on-site may still need to account for supplier and product-use impacts when justifying its scope boundary.

⚠️ A gap worth closing before an audit tests it: a documented statement that a factor (say, biodiversity) was considered and found not material is defensible. Silence on it is not. Auditors are trained to look for evidence of consideration, not necessarily a full formal assessment for every factor.

If you are updating your context analysis for the first time under 2026 → don’t treat this as a rewrite. Add the five named factors to your existing context documentation, extend your scope justification to address life-cycle control and influence under 4.3, and note your rationale where a factor doesn’t apply to your operation.


Clause 5: Leadership

No new sub-clauses were added to Clause 5, and the changes here are clarifications and strengthened emphasis rather than a wholesale redesign — but it isn’t purely a matter of tone, either. The policy note under 5.2 has been expanded to explicitly reference commitment to the preservation or conservation of natural resources, and the documented-information language shifts from “fulfil” to “meet” for compliance obligations. If your environmental policy is due for review during the transition window, this is a natural point to incorporate the expanded commitment language.

Beyond that wording update, certification bodies are signaling that auditors will expect more visible evidence of personal top-management engagement — not just a signed environmental policy and calendar attendance at the annual management review. Accountability, integration of environmental objectives into business planning, and alignment with strategic direction were always required; the 2026 revision keeps the pressure on without adding new formal sub-clause requirements.

A common finding going into transition audits: leadership commitment that exists on paper (signed policy, meeting minutes) but isn’t traceable to an actual business decision — a capital allocation, a supplier contract clause, a product design change. That traceability is what auditors are being trained to probe for.


Clause 6: Planning

Clause 6 sees the most structural change of any section in the revised standard, split across three areas.

6.1 Actions to Address Risks and Opportunities

The core planning clause — environmental aspects, compliance obligations, risk-based thinking — isn’t redesigned, but it’s restructured for clarity. Most of the general content that lived in 2015’s Clause 6.1.1 has been moved into a new dedicated sub-clause, and the former “planning actions” content is renumbered to 6.1.5.

New Clause 6.1.4 (Risks and opportunities) gives risks and opportunities their own dedicated sub-clause for the first time. It requires the organization to determine which risks and opportunities — arising from its 4.1 context, 4.2 interested-party needs, and 4.3 scope — need to be addressed, and to make that determination available as documented information. Important nuance: the standard does not prescribe a specific document format called a “risks-and-opportunities register.” If your current system scatters this information across aspect registers, compliance logs, and planning documents, 6.1.4 is a good opportunity to make the connection more explicit and traceable — but a register isn’t a mandatory artifact, just a common and defensible way to demonstrate it.

6.1.2 (Environmental aspects) strengthens the life-cycle perspective that already existed in 2015, with a new note clarifying that environmental risk planning — including identification, assessment, and emergency-situation determination — must consider the life-cycle perspective. This is the clause connecting most directly to Clause 8.1 below — if your supplier flow-down documentation is thin, both clauses will surface it.

6.3 Planning of Changes — The One Genuinely New Clause

ISO 14001:2026 clauses explained with a practical Clause 6.3 planning of changes workflow for an environmental management system
ISO 14001:2026 clauses explained through a practical Clause 6.3 workflow for identifying, planning, implementing, and verifying EMS changes.

This is the headline change in the entire revision. Clause 6.3 did not exist in ISO 14001:2015. It requires organizations to determine, plan, and manage changes that affect — or could affect — the intended outcomes of the EMS, and to carry those changes out in a planned, controlled manner.

If you’re also certified to ISO 9001, this will look immediately familiar — ISO 9001:2015 has had a change management clause since its last revision. ISO 14001 is catching up, and for integrated management systems this closes one of the more persistent structural mismatches between the two standards. In the 2015 edition, environmental change management lived piecemeal across multiple clauses with no single anchor point. The 2026 edition gives it one.

If you are running an integrated management system (ISO 9001 + ISO 14001) → extend your existing ISO 9001 clause 6.3 change-management procedure rather than building a parallel one from scratch. Keep the risks-and-opportunities information clearly identifiable and traceable under 6.1.4, even if the underlying process is shared.


Clause 7: Support

Structurally unchanged. The documented-information terminology is refreshed to match the vocabulary used across the rest of the 2026 edition, but the substantive requirements — competence, awareness, communication, control of documented information — carry over from 2015 without new “shall” statements.

Objection worth naming here: “Do we need to rebuild our entire document control system for this?” No. If your EMS documentation was compliant under 2015, the structure doesn’t need rebuilding. What needs review is whether the terminology and cross-references in your procedures still match the clause numbering and vocabulary used in the 2026 text — a find-and-replace exercise, not a redesign.


Clause 8: Operation

Clause 8.1 (Operational planning and control) is broadened, and this is the second most consequential change in the revision after Clause 6.3. The 2026 edition replaces the 2015 term “outsourced processes” with “externally provided processes, products and services” — a deliberately wider scope that extends environmental accountability further into your supply chain, not just the processes you’ve formally outsourced.

This connects directly back to Clause 6.1.2’s strengthened life-cycle perspective and Clause 4.3’s scope requirements. Together, these clauses are where auditors will spend more time in a transition audit than anywhere else in the standard.

ISO 14001:2026 clauses explained through the life-cycle perspective connecting Clause 6.1.2 environmental aspects with Clause 8.1 external controls
ISO 14001:2026 clauses explained through the life-cycle perspective from raw materials and suppliers through manufacturing, distribution, product use, and end of life.

If you are under customer pressure to demonstrate supply chain environmental controls → this is the clause pairing to get ahead of first. Supplier questionnaires, flow-down clauses in purchase orders, and documented supplier evaluation criteria all become more defensible evidence under the 2026 text than a general “we expect suppliers to comply” statement.


Clause 9: Performance Evaluation

This clause carries two real structural changes and deserves the same depth as Clause 7.

Clause 9.2.2 (Internal audit programme) now explicitly requires audit objectives, alongside the existing scope and criteria elements, as part of every internal audit. This is a small addition in word count but a real one in practice: “verify we’re ready for the certification audit” doesn’t meet the intent. A defensible objective looks more like “verify conformance of the updated EMS to the 2026 requirements, with particular focus on Clauses 4.1, 6.1.4, 6.3, and 8.1” — specific, testable, and tied to what actually changed.

Clause 9.3 (Management review) is restructured from a single clause into three sub-clauses: 9.3.1 General, 9.3.2 Management review inputs, and 9.3.3 Management review results. The required inputs and results are substantially preserved from 2015 — this is a structural reorganization more than a content rewrite — but your management review agenda and meeting-minutes template should be updated to reflect the new sub-clause structure so your documented information maps cleanly to what an auditor will be checking against.

Monitoring, measurement, analysis, and evaluation requirements outside these two areas carry over largely intact. What auditors are being trained to check more closely is whether performance evaluation data actually feeds into the Clause 6.3 change-planning process — in other words, whether your monitoring results are driving documented EMS changes, not just sitting in a report.


Clause 10: Improvement

The 2015 and 2026 structures line up like this:

2015 Edition2026 Edition
10.1 General10.1 Continual improvement
10.2 Nonconformity and corrective action10.2 Nonconformity and corrective action
10.3 Continual improvement

Clause 10.1 and 10.3 from the 2015 edition are merged into a single renumbered Clause 10.1, “Continual improvement.” This is a structural consolidation with two accompanying wording updates rather than a new requirement — nonconformity and corrective action content stays at 10.2 and is unaffected in substance, only in how the surrounding clauses are numbered and referenced.

If your procedures cross-reference clause numbers directly (a common practice in older EMS documentation) → this is the one place a pure numbering change can create a real nonconformity if your document control doesn’t catch it. Update cross-references before your transition audit, not during it.


Transition Timeline: What Happens and By When

MilestoneDateWhat It Means
ISO 14001:2026 publishedApril 15, 2026The 2015 edition is formally superseded
New certifications to 2015 edition stopOctober 31, 2027Certification bodies stop issuing fresh 2015 certificates — 18 months after publication
Recertification audits incorporate transition activitiesOctober 1, 2027Under published certification-body schedules (e.g., Amtivo) — not a universal UKAS date; confirm with your own registrar
Final transition deadlineApril 30, 2029ISO 14001:2015 certificates are no longer valid after this date
ISO 14001:2026 clauses explained with a transition timeline from publication through the 2029 certification deadline
ISO 14001:2026 clauses explained with key publication, certification transition, and final deadline milestones.

A three-year transition window is standard practice for a major ISO management system revision under IAF rules — it mirrors the timelines used for ISO 9001:2015 and ISO 45001:2018. UKAS’s published technical bulletin confirms both dates directly: certification bodies must transition their certified customers by April 30, 2029, and stop issuing new ISO 14001:2015 certificates after 18 months from publication. Many organizations fold the transition into a scheduled surveillance or recertification audit rather than scheduling a standalone transition audit, which reduces duplicated audit activity — though additional audit time, training, or documentation work should still be budgeted for depending on your certification body’s approach.

⚠️ Certification bodies are still finalizing their own auditor training and accreditation updates for the 2026 edition. If you’re scheduling a transition audit in the next few months, confirm directly with your certification body which clauses their auditors are currently trained to assess — you can verify a certification body’s accredited scope through ANAB if you want independent confirmation beyond what the registrar tells you — since availability and readiness vary by registrar.

A common transition failure isn’t that the work is hard — it’s assuming a scheduled recertification audit will automatically cover the new edition. Confirm with your registrar now whether your next audit is scoped for the 2026 transition →

Get the ISO 9001 Roadmap — a step-by-step framework for sequencing management system implementation and updates without missing a deadline.


Where to Buy ISO 14001:2026 and Get Trained

The ANSI Webstore remains the preferred source for the official current edition — it serves international buyers and offers standards in multiple languages, which matters if you’re managing EMS documentation across more than one country. ISO 14001:2026 — ANSI Webstore. Use code CC2026 for 5% off any standard purchase through December 31, 2026.

If you’re building out a broader environmental documentation set, the ISO 14001 Collection bundles related standards at a lower combined cost than buying individually.

For internal auditor training on the revised clauses, both ISOQAR and BSI Group offer current courses covering the 2026 changes — worth comparing both since training format and pacing differ between the two providers. For a fuller side-by-side, see our BSI vs ISOQAR comparison.

If you are ready to buy the standard today → go with ANSI Webstore for the official edition. If you are still evaluating training providers → compare ISOQAR and BSI directly before committing budget. If you are building documentation from scratch → start with the ISO Documentation Kits for Manufacturers page rather than a generic template search.


Quick Audit Checklist

Use this as a fast pre-transition scan — not a substitute for a full gap assessment.

  • ✅ Context analysis (4.1/4.2) explicitly names all five environmental conditions: climate change, biodiversity, pollution, resource availability, and ecosystem health
  • ✅ A documented rationale exists for any named factor deemed not material
  • ✅ EMS scope statement (4.3) addresses control and influence across upstream and downstream life-cycle stages
  • ✅ Risks and opportunities (6.1.4) are identified, traceable, and available as documented information — register format optional
  • ✅ Life-cycle perspective (6.1.2) documentation addresses upstream supplier and downstream product impact
  • ✅ A change-management procedure exists and is mapped to Clause 6.3 — shared with ISO 9001 if integrated
  • ✅ Supplier and externally-provided-process flow-down and evaluation criteria (8.1) go beyond a general compliance statement
  • ✅ Internal audit programme documentation includes defined audit objectives (9.2.2)
  • ✅ Management review agenda and minutes template reflect the 9.3.1/9.3.2/9.3.3 structure
  • ✅ Internal procedures cross-referencing old clause numbers (especially 10.1–10.3) have been updated

FAQ

Is ISO 14001:2026 a completely new standard?

No. The revision keeps the ten-clause Harmonized Structure and PDCA model, but reorganizes several sub-clauses, clarifies requirements, and adds the new 6.3 Planning of Changes.

What is the actual deadline to transition my certificate?

April 30, 2029, per UKAS’s published technical bulletin for accredited certification bodies. Certification bodies must also stop issuing new ISO 14001:2015 certificates by October 31, 2027. Confirm both dates with your own certification body, since national accreditation bodies outside the UK may communicate on slightly different timelines.

Do I need to rebuild my entire EMS documentation?

Generally, no. Organizations with a mature, well-run EMS under the 2015 edition should not need to start from scratch. The clarified expectations concentrate in specific clauses — primarily 4.1, 4.2, 4.3, 6.1.4, 6.3, 8.1, 9.2.2, and 9.3 — not the full documentation set.

What is the one genuinely new requirement in ISO 14001:2026?

Clause 6.3, Planning of Changes. It requires a formal, planned approach to managing changes affecting the EMS. It did not exist in any form in the 2015 edition.

Does the 2024 Climate Change Amendment still apply separately?

No. Amendment 1:2024, which introduced climate change considerations into clauses 4.1 and 4.2, has been formally integrated into the 2026 edition. If you already addressed the amendment, you’re ahead of most of this revision.

Will my certification body’s auditors already know the new requirements?

Not universally yet. Certification bodies are still completing their own auditor training and accreditation updates for the 2026 edition. Confirm directly with your registrar which clauses their auditors are currently trained and accredited to assess before scheduling a transition audit.

Does this revision affect integration with ISO 9001 or ISO 45001?

It improves it. Clause 6.3 closes a structural gap that previously existed between ISO 14001 and its Harmonized Structure siblings — ISO 9001 has had a change-management clause since 2015. Integrated management systems should find alignment easier, not harder, under the 2026 edition.

Should I certify directly to ISO 14001:2026 if I’m not yet certified to any edition?

If you’re implementing an EMS for the first time, there’s little reason to build to the 2015 edition and then transition. Go directly to the 2026 requirements.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts

Not Sure What to Do Next?

🔹 Still researching what changed? Start with our ISO 14001:2026 vs 2015: What’s New at a Glance for the condensed version, then bookmark this clause-by-clause breakdown as your reference.

🔹 Ready to start closing gaps? Run the Manufacturing Compliance Checklist against Clauses 4.1, 4.3, 6.1.4, 6.3, 8.1, and 9.2–9.3 first — that’s where the substantive changes concentrate.

🔹 Need to buy the standard or get your team trained? ISO 14001:2026 — ANSI Webstore for the standard itself, or compare ISOQAR and BSI Group for internal auditor training on the revised clauses.

The revision cycle rewards the organizations that mapped their EMS to the new clauses early — not the ones that waited for the deadline to force the issue. That’s the difference between a transition audit that folds into your normal surveillance cycle and one that turns into a scramble.

The Standards Navigator will keep tracking this transition as certification bodies finalize their auditor guidance.


Every Revision Cycle Produces the Same Split

Some EMS teams treat a standard revision as a scramble that starts the month before their transition audit. Others map the changed clauses the week the new edition publishes and fold the update into their next scheduled surveillance visit. The difference isn’t resources — it’s whether someone read the clause-by-clause changes before the deadline was the only thing driving the timeline.

The Standards Navigator covers ISO 14001, ISO 9001, and ISO 45001 clause-by-clause — not just certification overviews — because the clause level is where audit findings actually happen.

👉 Get updates on ISO 14001:2026 transition guidance as certification bodies finalize their timelines
👉 Be first to access new EMS gap-assessment resources as they’re built

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO 13485 Clauses Explained: A Complete Clause-by-Clause Breakdown (2026)

ISO 13485:2016 has eight clauses, but only five carry auditable requirements. This ISO 13485 clauses explained guide breaks down Clauses 4 through 8 in practical terms, corrects the common DHF-to-Medical-Device-File mapping error, and explains how FDA’s Compliance Program 7382.850 — which replaced QSIT on February 2, 2026 — reorganizes inspections around six QMS Areas and four Other Applicable FDA Requirements.

What every section of ISO 13485:2016 actually requires — and where auditors dig deepest

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Standard Reads Like a Checklist. It Isn’t One.

ISO 13485:2016 has eight clauses. Five of them carry actual requirements. That structure looks simple on the page — and it’s exactly why so many quality teams underestimate how much interpretation each clause demands once an auditor starts asking “show me.” This ISO 13485 clauses explained guide breaks down what each section requires, where the requirements overlap, and what auditors and FDA investigators may look for.

The FDA’s Quality Management System Regulation (QMSR) took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That changes what this clause structure means in practice. FDA also replaced its inspection methodology the same day — the Quality System Inspection Technique (QSIT) is gone, replaced by Compliance Program 7382.850. Getting the clause boundaries right now has a direct line to how an FDA investigator scopes an inspection, not just how a certification body audits.

Regulatory affairs and quality professionals reading this already know ISO 13485 exists. What’s harder to find is a breakdown that goes past the clause titles and into what each section demands in practice — where the audit findings cluster, where risk management threads through clauses that don’t mention risk in their title, and where the standard’s lack of an Annex SL high-level structure changes how it should be read compared to ISO 9001.

My perspective on this comes from 25+ years in operations leadership, an ISO 9001 Internal Auditor certification, and a Six Sigma Green Belt — a lot of that time spent on both sides of the table, building QMS documentation and sitting in CAPA reviews when a gap in that documentation turned into a finding. The pattern holds across every regulated QMS I’ve worked with: teams don’t fail because they misread a clause. They fail because they treated clause boundaries as more rigid than the standard actually intends, and missed how much cross-referencing an auditor expects between clauses 4 through 8.

If you haven’t run a structured gap check against the current clause set, that’s the place to start — not a full documentation rewrite.

👉 Run the ISO 13485 Gap Assessment Checklist before you touch your quality manual — a free, structured way to see exactly which clauses your QMS already satisfies and which ones need real work before an auditor finds the gap for you.


In This Guide

  • How ISO 13485:2016 is structured, and why it doesn’t follow ISO’s Annex SL format
  • A clause-by-clause breakdown of Clauses 4 through 8
  • How FDA’s current inspection program, Compliance Program 7382.850, reorganizes inspections around six QMS Areas
  • The most common audit findings tied to specific sub-clauses
  • Where risk management actually appears throughout the standard
  • How ISO 13485 clause numbering compares to ISO 9001
  • FAQs on structure, exclusions, and transition timing


👉 Start Here (Top Resources)


ISO 13485 Clauses Explained: How the Standard Is Structured

ISO 13485 clauses explained with an eight-clause map covering the standard’s foundational and QMS requirement clauses
ISO 13485 clauses explained through an eight-clause map showing the foundational clauses and the five clauses containing QMS requirements.

ISO 13485:2016 is built around eight clauses. The first three are introductory — they define scope, point to normative references, and set terminology. They carry no auditable requirements on their own, but skipping them is a mistake most teams make once and then correct the hard way.

Clauses 4 through 8 are where the requirements live. This is the part of the standard your certification body actually audits against, clause by clause, sub-clause by sub-clause.

Here’s something worth knowing before you go further: ISO 13485 does not follow the Annex SL high-level structure that ISO 9001:2015, ISO 14001, and ISO 45001 all share. Those three standards align clause-for-clause at the top level, which is why integrated management systems work so cleanly across them. ISO 13485 kept its own structure when it was revised in 2016, specifically so it could stay independent of ISO 9001 revision cycles — a deliberate choice by the technical committee to protect regulatory stability for device manufacturers. If you’re coming from an ISO 9001 background, this is the first adjustment to make: don’t assume clause 7 means the same thing in both standards. It doesn’t.


Clauses 1 Through 3: No Requirements, But Don’t Skip Them

Clause 1 (Scope) defines what the standard covers and, critically, how exclusion and non-application work. ISO 13485 doesn’t let an organization simply skip a requirement that seems inconvenient — where a clause is excluded or considered non-applicable (say, you don’t perform installation), the scope and justification have to be documented in the quality manual under Clause 4.2.2, and be prepared to defend that justification during an audit.

Clause 2 (Normative References) points to ISO 9000:2015 for terms and definitions. You don’t need to buy ISO 9000 to comply, but auditors do expect your team to be using its vocabulary consistently — “nonconformity,” “corrective action,” and “verification” all carry specific meanings your documentation should match.

Clause 3 (Terms and Definitions) establishes the vocabulary used throughout the standard, including specific definitions for concepts like medical device, complaint, risk, and post-market surveillance. Getting comfortable with this terminology matters more than it looks like it should — auditors expect your documentation to use these terms precisely, not colloquially.

📥 Before diving into clauses 4-8: if your QMS documentation predates 2020, run it against the current ISO 13485 Documentation Requirements breakdown first. Most gaps trace back to documentation structure, not missing procedures.


Clause 4: Quality Management System

Clause 4 sets the general requirements for the QMS itself — and it’s where most audit programs start, because everything downstream depends on it.

4.1 General Requirements requires you to identify your QMS processes, map their sequence and interaction, and — this is the part that trips up contract manufacturers — maintain control over any process you outsource. Most common finding: outsourced processes (contract sterilization, contract testing, third-party calibration) that exist operationally but were never formally brought into QMS scope. If a supplier touches your product or your data, your QMS has to account for it.

4.2 Documentation Requirements covers the quality manual, the Medical Device File (Clause 4.2.3), document control, and record control. This requirement is specific to this standard — it’s not something ISO 9001 asks for. It’s a defined set of documents and references demonstrating a device meets its requirements throughout its lifecycle, and auditors will ask to see it assembled, not scattered across a dozen disconnected folders.

If your documentation still uses FDA’s old terminology, this is worth getting precise about. As of February 2, 2026, the terms Device Master Record, Device History Record, and Design History File no longer appear in 21 CFR Part 820. Those legacy record concepts weren’t simply eliminated; their applicable requirements are now addressed through the QMSR framework and ISO 13485’s own structure. Most of what a Device Master Record covered lives in the Medical Device File at Clause 4.2.3, while the Design History File corresponds to the Design and Development File at Clause 7.3.10. These aren’t simple one-for-one renamings: the Medical Device File in particular is a broader requirement than the DMR it replaced, so a straight terminology swap in your documentation will likely leave gaps a crosswalk exercise would catch.

Sub-clause 4.2.4 (control of documentation) and 4.2.5 (control of records) get their own scrutiny. Auditors typically check three things here: are documents reviewed and approved before use, is there a mechanism to prevent use of outdated versions, and are records retained for a defined, justified period. If you’re preparing for your first audit under this clause → build your document control procedure before you build anything else. Everything else in the QMS references it.


Clause 5: Management Responsibility

Clause 5 puts specific, named accountability on top management — not “the quality department,” but leadership itself.

This clause requires a documented quality policy, measurable quality objectives, evidence of planning for QMS changes, and a sub-clause I’ve seen come up repeatedly in audit findings — management review. Clause 5.6.2 is unusually prescriptive for an ISO standard: it names twelve required inputs, and a compliant management review record has to address all of them or document why one doesn’t apply — feedback, complaint handling, reporting to regulatory authorities, audits, monitoring and measurement of processes, monitoring and measurement of product, corrective action, preventive action, follow-up actions from previous reviews, changes that could affect the QMS, recommendations for improvement, and applicable new or revised regulatory requirements. A management review that skips several of these, or that doesn’t produce documented outputs and action items, is a finding waiting to happen — and under the current FDA inspection framework, it’s no longer just a certification-audit concern (more on that below).

If you are already ISO 9001 certified, this clause will feel familiar structurally — but ISO 13485 expects a tighter link between management review and regulatory requirements specifically, not just general business objectives.


Clause 6: Resource Management

Clause 6 covers human resources, infrastructure, and work environment — including contamination-control requirements under 6.4.2 that go considerably further than ISO 9001’s general treatment of work environment.

6.2 Human Resources requires documented competence for anyone whose work affects product quality — not just “trained,” but competence tied to education, skills, and experience, with evidence. 6.3 Infrastructure requires maintenance records for equipment critical to product conformity. 6.4 Work Environment and Contamination Control is where device manufacturers doing anything sterile, implantable, or otherwise contamination-sensitive get the most detailed scrutiny — cleanroom classifications, gowning procedures, and environmental monitoring data all trace back here.


Clause 7: Product Realization

Clause 7 is the largest clause in the standard, and it’s where design controls, purchasing, production, and servicing all live.

7.1 Planning of Product Realization is where ISO 13485 explicitly requires documented risk management processes within product realization, with records maintained throughout. The clause’s note points readers to ISO 14971 for further guidance on structuring that risk management activity — it’s a reference, not a formal incorporation, though in practice most organizations end up using ISO 14971’s framework to satisfy this requirement.

7.3 Design and Development is one of the sub-clauses most commonly identified as non-applicable by contract manufacturers who don’t design product — but where it applies, it can’t be excluded lightly, and the justification has to hold up to the same Clause 4.2.2 scrutiny as any other exclusion. If it applies to you, this is the densest technical section of the standard: design inputs, outputs, review, verification, validation, transfer, and change control, each with its own documented evidence trail. Most common finding: design changes made without running them back through the full verification/validation cycle, especially late in development when schedule pressure is highest.

7.4 Purchasing requires supplier evaluation criteria proportionate to risk, and re-evaluation triggers when supplier performance changes. 7.5 Production and Service Provision covers process validation for anything that can’t be fully verified by downstream inspection — sterilization is the textbook example, which is why it gets its own dedicated body of standards. 7.6 Control of Monitoring and Measuring Equipment ties directly into your calibration program.

If you are under customer or FDA pressure to show design control maturity quickly → prioritize closing out 7.3 documentation gaps before anything else in this clause. In my experience, it’s one of the first sections a regulatory reviewer or auditor asks to see in depth.


Clause 8: Measurement, Analysis and Improvement

Clause 8 is where the QMS proves it’s actually working — and where CAPA lives.

8.2 Monitoring and Measurement covers feedback, complaint handling, and internal audit. Complaint handling under this clause has to interface with FDA’s separate adverse-event reporting requirements — a complaint that may represent a reportable event under Medical Device Reporting (21 CFR Part 803) can’t remain solely an internal QMS record; it has to be evaluated independently against those reporting obligations.

8.3 Control of Nonconforming Product requires documented procedures for identifying, segregating, and dispositioning nonconforming product, including for product discovered nonconforming after delivery — which is where recall-adjacent procedures connect back into the standard.

8.5 Improvement is where corrective and preventive action requirements sit. CAPA under ISO 13485 requires root cause investigation, verification that the action taken was effective, and — a detail I’ve seen auditors check for specifically — evidence that you evaluated whether the same nonconformity could exist elsewhere in the organization before closing the CAPA. A CAPA record that fixes one instance without documenting that broader check is incomplete by this clause’s own standard, regardless of whether the immediate fix worked.

For a deeper breakdown of this clause specifically, see our full guide to CAPA requirements in ISO 13485.


Where ISO 13485 and FDA’s QMSR Overlap by Clause

FDA’s Quality Management System Regulation took effect February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820. That’s the headline most coverage stopped at. What matters more for how you prepare is what happened on the inspection side the same day: FDA retired the Quality System Inspection Technique (QSIT), the inspection methodology it had used since 1999, and replaced it with a new compliance program manual — CP 7382.850, Inspection of Medical Device Manufacturers.

ISO 13485 clauses explained through the 2026 FDA QMSR inspection framework, including six QMS Areas and four OAFRs
ISO 13485 clauses explained in the context of the FDA QMSR and CP 7382.850 inspection framework effective February 2, 2026.

QSIT organized inspections around four subsystems. CP 7382.850 reorganizes them around six QMS Areas, each mapped to ISO 13485 clauses with FDA-specific requirements layered in:

  • Management Oversight — the QMS itself, management review, the medical device file, and product realization planning
  • Design and Development — design inputs, outputs, review, verification, validation, software validation, and transfer
  • Production and Service Provision — production planning, process validation, and servicing
  • Measurement, Analysis, and Improvement — complaint handling, feedback, internal audits, corrective and preventive action, and control of nonconforming product
  • Outsourcing and Purchasing — supplier evaluation and control
  • Change Control — how changes to product or process are managed and documented

Alongside the six QMS Areas, inspections also evaluate four Other Applicable FDA Requirements (OAFRs) that sit outside ISO 13485’s text entirely: Medical Device Reporting (21 CFR Part 803), Corrections and Removals reporting (21 CFR Part 806), Medical Device Tracking (21 CFR Part 821), and Unique Device Identification (21 CFR Part 830). This is where the clause structure above stops covering everything — these four areas are FDA-specific regulatory obligations, not ISO 13485 requirements. They’re evaluated during routine surveillance, compliance follow-up, and PMA postmarket inspections; a narrow exception can apply to certain PMA preapproval inspections when the manufacturer hasn’t yet introduced the device to the U.S. market.

The change that affects Clause 5 most directly: under the prior QSR, management review records were categorically exempt from FDA review under §820.180(c). Under CP 7382.850, that exemption is gone. Management review now sits squarely inside the Management Oversight QMS Area, and an investigator can ask to see it — which means the twelve required Clause 5.6.2 inputs covered above aren’t just a certification-audit concern anymore.

One caution worth stating plainly: ISO 13485 certification and FDA QMSR compliance are related but not identical. A QMS built cleanly against Clauses 4 through 8 covers the ISO 13485 core that QMSR incorporates, but it doesn’t automatically satisfy the four OAFRs — those require their own documented processes regardless of how strong your clause-by-clause QMS is.

If you’re not sure whether your current documentation satisfies both frameworks → our FDA QSR vs ISO 13485 comparison and MDSAP vs ISO 13485 breakdown both walk through this in more detail than fits here.

ISO 13485 vs ISO 9001: Same Numbers, Different Weight

ElementISO 13485:2016ISO 9001:2015
Structure8 clauses, own structure (not Annex SL)10 clauses, Annex SL high-level structure
Risk managementDocumented risk management required in product realization (7.1); note references ISO 14971Risk-based thinking, less prescriptive
Customer satisfaction monitoringNo direct ISO 9001-style requirement; feedback/complaints addressed via Clause 8.2Explicit requirement (Clause 9.1.2)
DocumentationMedical device file required (Clause 4.2)No equivalent requirement
Design controlsDetailed, mandatory unless justified exclusionLess detailed by comparison
Regulatory linkDirectly referenced in FDA QMSR (21 CFR 820)Not tied to a specific regulation

The clause numbers look similar enough to cause real confusion — both standards use “Clause 7” for a large operational section, but the content underneath diverges substantially. If your organization holds both certifications, don’t assume a clause 7 audit finding under one standard tells you anything about your standing under the other. For the full comparison, see ISO 9001 vs ISO 13485.

The objection I hear most on this topic: “We’re already ISO 9001 certified — how much of this is actually new work?” Realistically, expect Clauses 5 and 6 to require the least rework, since management responsibility and resource management overlap heavily in intent. Clauses 4, 7, and 8 are where the medical device-specific requirements add real documentation and process work — the medical device file, design control rigor, and CAPA’s broader-impact evaluation aren’t things a general ISO 9001 QMS already has built in.


Most teams don’t fail an ISO 13485 audit because they misunderstood a clause. They fail because they assumed a documented procedure was enough without checking whether it actually produces the evidence an auditor will ask to see.

👉 Run a structured check before that assumption gets tested in front of an auditor → ISO 13485 Gap Assessment Checklist


Quick Clause Reference Checklist

A clause tells you what’s required. It doesn’t tell you what to hand an auditor when they ask for proof. Below is a quick translation — clause by clause, requirement to evidence.

ISO 13485 clauses explained through an audit evidence checklist showing objective evidence for Clauses 4, 5, 7, and 8
ISO 13485 clauses explained through the objective evidence auditors may review for Clauses 4, 5, 7, and 8.

✅ Clause 4 — QMS scope defined, outsourced processes controlled, medical device file assembled
✅ Clause 5 — Quality policy documented, management review covering all required inputs
✅ Clause 6 — Competence records current, contamination controls documented where applicable
✅ Clause 7 — Risk management documented within product realization; ISO 14971 provides further guidance; design control records complete, supplier evaluation criteria defined
✅ Clause 8 — Complaint handling tied to regulatory reporting, CAPA records show broader-impact evaluation

⚠️ Clauses 1–3 — Exclusions and non-applicability justified in the quality manual, not just left blank

For implementation sequencing beyond the checklist above, our ISO 13485 Implementation Roadmap and ISO 13485 Gap Assessment: Step-by-Step Guide walk through the order to tackle these in.


FAQ

How many clauses does ISO 13485:2016 have?

Eight. Clauses 1 through 3 are introductory and carry no auditable requirements. Clauses 4 through 8 contain the substantive quality management system requirements that certification bodies audit against — and since February 2026, FDA investigators evaluate the same core requirements under Compliance Program 7382.850.

Does ISO 13485 follow the same structure as ISO 9001?

No. ISO 13485 does not use ISO’s Annex SL high-level structure, which ISO 9001, ISO 14001, and ISO 45001 all share. The technical committee kept ISO 13485 independent specifically to protect regulatory stability for device manufacturers, so clause numbers that look similar between the two standards often cover different scope.

Can I exclude clauses from ISO 13485?

Only with documented justification. Under Clause 4.2.2, the scope and justification for any exclusion or non-application have to be recorded in the quality manual, and you need to be prepared to defend that justification during an audit.

Which ISO 13485 clause covers risk management?

Clause 7.1 (Planning of Product Realization) is where documented risk management is explicitly required, and its note points to ISO 14971 for further guidance. But risk-related requirements aren’t confined to one clause — they surface throughout Clauses 4 through 8 rather than sitting in a single isolated section.

What’s the difference between ISO 13485 and the FDA’s QMSR?

As of February 2, 2026, FDA’s QMSR incorporates ISO 13485:2016 by reference into 21 CFR Part 820, and FDA’s inspection methodology changed to match — Compliance Program 7382.850 replaced QSIT the same day. The two frameworks are far more tightly aligned than before, but they’re not identical: four Other Applicable FDA Requirements (Medical Device Reporting, Corrections and Removals, Medical Device Tracking, and UDI) sit outside ISO 13485’s text and are evaluated in applicable inspection types, with a limited exception for certain PMA preapproval inspections when the device has not yet been introduced to the U.S. market.

What is CP 7382.850?

CP 7382.850 (Inspection of Medical Device Manufacturers) is FDA’s current compliance program manual for device inspections, effective February 2, 2026 alongside the QMSR. It replaced the Quality System Inspection Technique (QSIT) and reorganizes inspections around six QMS Areas — Management Oversight, Design and Development, Production and Service Provision, Measurement/Analysis/Improvement, Outsourcing and Purchasing, and Change Control — plus four Other Applicable FDA Requirements evaluated in most inspection types.

Do I need to buy ISO 9001 to understand ISO 13485’s terminology?

You don’t need to purchase it, but ISO 13485 does reference ISO 9000:2015 for its terms and definitions, and auditors expect consistent use of that vocabulary in your documentation.

Which clauses deserve the closest audit preparation?

In practice, Clause 4.2 (documentation control), Clause 7.3 where applicable (design and development), and Clause 8.5 (CAPA effectiveness) tend to draw sustained attention, largely because each requires ongoing documented evidence rather than a one-time procedure. The exact focus varies by organization, device type, and regulatory scope — under the current FDA inspection framework, Management Oversight and Measurement, Analysis, and Improvement are evaluated on every inspection regardless of device type.

Is a documentation kit enough to get ISO 13485 clause requirements right?

A kit gives you a starting structure, but clause-by-clause compliance depends on evidence specific to your processes — training records, design and development records, CAPA effectiveness checks. Our ISO Documentation Kits for Manufacturers page breaks down what a kit does and doesn’t cover.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching how the clauses fit together? Start with What Is ISO 13485? for the foundational overview before working through this clause breakdown a second time.

🔹 Ready to assess where your QMS actually stands? Run the ISO 13485 Gap Assessment Checklist against the clause list above — it’s built to map directly to Clauses 4 through 8.

🔹 Need the official standard text to cite exact clause language? Purchase ISO 13485:2016 through ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. International-language editions are available for teams managing documentation across multiple regulatory regions.

🔹 Need your internal auditors trained on this clause structure before your next surveillance audit? ISO 13485 training through BSI Group covers the structure clause by clause with a certification body’s own instructors.

The Standards Navigator breaks down what these clauses actually demand — not just what they’re titled — so your team can walk into an audit knowing which sub-clause the finding will land on before it does.


Stay Ahead of Clause-Level Changes

Most QMS documentation doesn’t fail because a team ignored ISO 13485. It fails because someone mapped a procedure to the wrong clause once, early on, and every review since has confirmed the wrong thing.

Organizations that treat the clause structure above as a living reference — checked against actual audit findings, updated as FDA’s QMSR enforcement approach becomes clearer — walk into surveillance audits with far fewer surprises than organizations treating their quality manual as a document they wrote once and filed away.

The Standards Navigator tracks ISO 13485, QMSR, and the surrounding medical device standards landscape as they develop, not just at certification time.

👉 Get updates on ISO 13485 and medical device QMS requirements
👉 Be first to access new gap assessment tools and clause-mapping resources

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISOQAR Academy Training Review: Is It Worth It for Manufacturers in 2026?

ISOQAR Academy is the training division of certification body ISOQAR, offering CQI/IRCA-certified courses across ISO 9001, 14001, and 45001. This review breaks down course levels from foundation through lead auditor, distinguishes the IMS route from the auditor-conversion route, and covers what training costs and how to decide which level actually fits a given shop.

ISOQAR doesn’t just certify manufacturers — it trains them through ISOQAR Academy. Here’s what the courses actually cover, what they cost, and whether formal training is worth the investment for your shop

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you. The Standards Navigator is an authorized affiliate of ISOQAR.


Your Auditors Don’t Need a Certificate. They Need to Actually Be Competent.

Every ISO standard requires competent internal auditors. None of them requires you to buy a specific training course to get there.

That distinction matters, because training providers — ISOQAR included — will always make the case that their course is the fastest path to that competence. Sometimes it is. Sometimes your shop already has the in-house experience to get there a cheaper way. The question worth answering before you book anything is which path actually fits where your operation stands right now.

ISOQAR Academy is the training arm of ISOQAR, the UKAS-accredited certification body. It offers CQI/IRCA-certified auditor training alongside foundation and other ISO courses across ISO 9001, ISO 14001, ISO 45001, and ISO 27001, delivered both in person at UK training venues and through live virtual classrooms. This review breaks down what ISOQAR Academy training actually covers, what it costs, and how to decide whether it’s the most efficient way to build your team’s competence.

From the Floor: I’ve watched auditors who were genuinely sharp on ISO 9001 fundamentals still miss things once the audit crossed into AS9100-only territory — a configuration management record that didn’t tie back cleanly, a counterfeit-parts control that existed on paper but nobody on the floor could actually explain. That’s not a competence gap in the general sense. It’s a knowledge gap in the aerospace-specific clauses that ISO 9001 experience alone doesn’t cover. Training earns its cost closing that specific gap — it doesn’t replace the auditing fundamentals your team should already have walking in.

Before you book a course, know where your QMS actually stands. A gap assessment tells you which clauses need work before you decide who needs training and at what level.

📥 Download the ISO 9001 Roadmap — a step-by-step implementation guide that walks you from gap assessment through Stage 2 audit clearance, so you know exactly what training gap you’re actually closing.


In This Guide

  • What ISOQAR Academy is and how it fits alongside ISOQAR’s certification business
  • What each course level actually covers — foundation, internal auditor, integrated auditor, and lead auditor
  • The honest pros and cons of training through ISOQAR Academy
  • What it costs, and how the pricing model works
  • A decision framework: which course level fits your shop right now
  • How ISOQAR Academy compares to BSI Group’s training catalog
  • FAQ: CQI/IRCA accreditation, in-house delivery, and what training does and doesn’t guarantee


👉 Start Here: Where to Look Into ISOQAR Academy Training

If your shop is evaluating formal ISO training, ISOQAR Academy’s course catalog spans foundation, internal auditor, and lead auditor levels across ISO 9001, ISO 14001, and ISO 45001. Review ISOQAR Academy’s current ISO 9001 training courses.

If you haven’t purchased a current copy of the standard yet, budget for it separately — course fees don’t always include it. Buy the current standard through the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.


What Is ISOQAR Academy?

ISOQAR Academy is the training division of ISOQAR, part of the Alcumus Group. While ISOQAR’s certification arm audits organizations against ISO standards, the Academy is a separate function that teaches teams how to understand and audit against those same standards — ISOQAR reports delivering over 8,000 hours of training to 10,000 participants each year.

Courses run through two delivery formats: classroom-based training at UK venues, and live virtual classroom sessions for teams who want to avoid travel cost and time away from the floor. In-house delivery is also available for shops training multiple employees at once, built around your own facility’s documentation rather than a generic case study.

A meaningful share of ISOQAR Academy’s auditor-level courses are CQI/IRCA-certified — accredited through the Chartered Quality Institute’s International Register of Certificated Auditors. That certification provides a formally recognized training credential, which can be useful when an individual’s training record needs to be demonstrated beyond their current employer, not just a course completion certificate.

A 2026 note on ISO 14001: ISOQAR Academy’s catalog is already transitioning ISO 14001 courses to the 2026 edition of the standard. If you’re booking ISO 14001 training, confirm which edition the specific course covers before enrolling — you don’t want your team trained against a superseded version while your certification body is auditing against the current one.


What ISOQAR Academy Courses Actually Cover

ISOQAR Academy training course levels for ISO auditors
ISOQAR Academy training ranges from foundation and internal auditor courses to IMS, CQI/IRCA conversion, and lead auditor training.

ISOQAR Academy’s course catalog isn’t one course — it’s a track, and most manufacturers only need the first one or two levels.

Course LevelWhat It CoversTypical LengthBest For
Foundation (single standard)Standard requirements clause by clause1 dayTeams new to a standard needing working familiarity before anything else
IMS FoundationIntroduces ISO 9001, ISO 14001, and ISO 45001 together, focused on the synergies between them1 dayTeams building familiarity across multiple standards from scratch
Internal Auditor (single standard)Planning, conducting, and reporting internal audits against one standard1 day (standard track) or 2 days (CQI/IRCA-certified)Teams ready to run their own audit program for a single standard
IMS Internal AuditorAuditing across ISO 9001, ISO 14001, and ISO 45001 in one course2 daysTeams already familiar with quality, environmental, or safety systems who need to audit all three together
Auditor Conversion (CQI/IRCA)Extends an existing single-standard auditor’s skills to add ISO 14001 and ISO 450013 daysAuditors already qualified in one standard who need to add EMS/OHS scope
Lead AuditorFull auditor competence for leading external or supplier audits5 daysDeveloping a professional auditing credential, not typical for a single shop’s internal program

A note on terminology: ISOQAR Academy doesn’t sell one generic “integrated auditor” course — it separates a from-scratch IMS Internal Auditor course (for teams building multi-standard audit capability together) from a CQI/IRCA conversion course (for auditors who already hold a single-standard credential and want to extend it). Confirm which one actually fits your team’s starting point before booking, since they assume different prior knowledge.

Most common finding: manufacturers default to booking internal auditor training as the first step, even when their team has never worked through the standard’s requirements in a structured setting. The foundation course exists for a reason — you can’t audit effectively against clauses your team doesn’t understand yet.

If you are new to a standard and still building your QMS → start with the foundation course, not internal auditor training.

If your team already understands the standard and just needs to run audits → the internal auditor course is the right entry point. CQI/IRCA-certified tracks provide a formally recognized training credential, which is useful if the individual’s training record ever needs to be demonstrated beyond this employer — a generic in-house version doesn’t carry that same portability.

If you’re pursuing certification across ISO 9001, 14001, and 45001 together and your team is starting from scratch → the IMS Internal Auditor course is built specifically for that, rather than sending your team through three separate single-standard courses.

If someone on your team is already a qualified auditor for one standard and you’re adding scope → the CQI/IRCA conversion course extends that existing credential to ISO 14001 and 45001, rather than starting them over with a from-scratch integrated course.


Pros and Cons of ISOQAR Academy Training

What ISOQAR Academy Does Well

  • CQI/IRCA-certified course tracks for internal and integrated auditor levels, providing a formally recognized training credential rather than just a generic completion certificate
  • Full course ladder from foundation through lead auditor, so you’re not stuck choosing between “too basic” and “too advanced”
  • Both classroom and live virtual delivery, with in-house options for training multiple employees at once
  • Courses cover ISO 9001, ISO 14001, ISO 45001, and ISO 27001 under one training provider
  • High course volume — ISOQAR reports delivering over 8,000 hours of training to 10,000 participants annually across course levels

Where ISOQAR Academy May Fall Short

  • Course pricing isn’t fully published for every format — in-house and group quotes typically require a direct request
  • Course value depends heavily on where your team already stands: a foundation course won’t add much for an experienced auditor, and an internal auditor course won’t help a team with no prior standard familiarity
  • Classroom locations are UK-based (Manchester, London, Bristol, Leamington Spa, and similar venues) — manufacturers outside the UK should confirm live virtual availability and time zone fit before booking
  • As with any training provider, actual instructor quality varies by who’s assigned to your specific session — a strong course catalog doesn’t guarantee every individual instructor is an equally strong fit for your industry

What ISOQAR Academy Training Costs

ISOQAR Academy doesn’t publish fixed pricing on its course pages — every course listing directs you to request details and book directly rather than showing a price upfront. That’s a call-for-quote model, not hidden pricing, but it does mean you can’t budget from the website alone. What’s generally true:

  • Individual seats on public courses are typically the standard entry point for one or two employees.
  • In-house delivery for multiple employees is worth comparing directly against per-seat pricing once you’re training several people — don’t assume one option is cheaper without requesting both quotes.
  • The standard itself usually isn’t included in the course fee. Budget separately for a current copy before class starts.
  • Live virtual delivery can meaningfully reduce total cost for smaller shops by cutting travel and time away from the floor, particularly for foundation-level courses that don’t require the same hands-on format as auditor training.

Because pricing isn’t published, request a written quote for your specific course, format, and group size before committing a budget — and get it in writing rather than relying on a verbal figure from an initial call.

If you haven’t priced out the full path to certification — training, documentation, gap assessment, and audit fees together — see the complete breakdown of ISO certification costs before committing to training in isolation.


Which Course Level Fits Your Shop?

Where you land depends on what competence already exists on your team — not on whether training is generically “a good idea.”

No prior experience with the standard and no internal audit experience on staff → Start with the foundation course. Booking internal auditor training before your team understands the standard’s requirements means teaching people to audit against clauses they haven’t learned yet.

Team already understands the standard but has never formally audited against it → The internal auditor course is the right level. A CQI/IRCA-certified track is worth the modest premium over a generic version if anyone might use the credential beyond this one employer.

Pursuing certification across multiple standards at once → The IMS Internal Auditor course (or the CQI/IRCA conversion course, if someone’s already qualified in one standard) is built for exactly this and avoids sending your team through three separate single-standard courses.

One experienced auditor already on staff → That person may be able to mentor others through the standard’s requirements without sending the whole team through a full course — formal training becomes most valuable for newer team members who don’t have that internal resource.

Multiple employees need the same training → Compare in-house group quotes against per-seat public course pricing before booking. In-house sessions built around your own documentation are usually the more efficient option past two or three people.

⚠️ Common mistake: booking lead auditor training as a first step before your shop has working documentation in place. That course assumes real familiarity with the standard already — it’s the wrong entry point for a team still building its QMS.


How ISOQAR Academy Compares to BSI Group Training

BSI Group runs a parallel training catalog and is the other name that comes up constantly in this conversation. Both providers offer foundation, internal auditor, and lead auditor courses across the major ISO standards, and both run CQI/IRCA-certified tracks at the auditor level.

FactorISOQAR AcademyBSI Group
Foundation courseYesYes
Internal auditor courseYesYes
Lead auditor courseYesYes
CQI/IRCA-certified tracksYesYes
Live virtual deliveryYesYes
In-house deliveryYesYes
UK classroom networkSmaller, regional venuesBroader national footprint

Neither provider wins universally — the practical differences tend to come down to course availability for your specific standard and format, instructor pool in your region, and quoted price for your group size, not a meaningful difference in the underlying accreditation of the courses themselves. Compare BSI Group’s ISO training courses alongside ISOQAR Academy before booking, particularly if you’re training multiple people and requesting in-house quotes from both.

For U.S. manufacturers specifically: both providers’ classroom networks are UK-based, so live virtual delivery is likely to be the practical default for a single-employee booking — reserve in-person or in-house formats for cases where you’re training several people at once and travel makes more sense.

If you’re already working with ISOQAR as your certification body → training through ISOQAR Academy keeps your documentation and terminology consistent with the language your certification auditor will use, though it isn’t required — you can train with one provider and certify with another.

If brand or provider isn’t a factor → request quotes from both and let course content, instructor experience, and price for your group size make the decision.


A Note on Certification vs. Training

ISOQAR Academy training vs certification for ISO management systems
ISOQAR Academy training builds auditor competence, while ISO certification independently evaluates whether a management system meets the applicable standard.

Worth being direct about this distinction: ISOQAR Academy trains your team. ISOQAR’s certification division audits your organization and issues your certificate. These are related but separate parts of the same company, and it’s a common point of confusion.

Completing an ISOQAR Academy course does not guarantee a smoother certification audit, whether that audit is conducted by ISOQAR or a different certification body entirely. Training builds competence — it doesn’t buy leniency, and the certification decision itself is a separate engagement with its own scope, quote, and timeline.

If you’re also evaluating which certification body to use — ISOQAR, BSI, or another UKAS-accredited provider — that’s a distinct decision from which training to book, and one worth researching separately. See the full breakdown of ISO certification bodies for that comparison.


ISOQAR Academy training readiness checklist for manufacturers
Use this ISOQAR Academy training checklist to match the right course to your team’s competence, audit experience, QMS readiness, and delivery needs.

Quick Checklist: Is Your Shop Ready to Book Training?

  • ✅ You’ve identified whether your team needs foundation-level or auditor-level training — not defaulted to auditor training by habit
  • ✅ You know whether you’re pursuing a single standard or an integrated audit across multiple standards
  • ✅ You’ve compared in-house group pricing against individual seat pricing for your team size
  • ✅ You’ve budgeted separately for the standard itself, since course fees typically don’t include it
  • ✅ You’ve confirmed live virtual availability if your shop is outside the UK or wants to avoid travel cost
  • ⚠️ If your QMS documentation isn’t far enough along to give auditors real processes and records to work with, reconsider the timing of internal auditor training — there’s little to practice against otherwise

FAQ

Does ISOQAR Academy training count toward certification?

No single training course is required for certification. What matters is that your internal auditors are genuinely competent to plan, conduct, and report an effective audit — training is one path to building that competence, not a certification requirement in itself. Your certification body will assess whether your organization has established and maintained personnel competent to carry out its management system and audit activities, not which specific course they attended.

Is ISOQAR Academy training CQI/IRCA accredited?

A meaningful portion of ISOQAR Academy’s internal auditor, IMS internal auditor, and conversion courses are CQI/IRCA-certified, accredited through the Chartered Quality Institute’s International Register of Certificated Auditors. Confirm accreditation status for the specific course you’re booking, since not every course level carries this certification.

Can I train with ISOQAR Academy and certify with a different body?

Yes. Training and certification are separate engagements, even when both are available through ISOQAR. You can complete ISOQAR Academy training and pursue certification with BSI, another UKAS-accredited body, or ISOQAR’s own certification division — whichever fits your shop’s needs.

How much does ISOQAR Academy training cost?

Pricing isn’t published on ISOQAR Academy’s course pages — course listings direct you to request details and book directly. Individual public-course seats are generally the entry point for one or two employees; in-house delivery is quoted separately and worth comparing directly once you’re training several people. Request a written quote for your specific course, format, and group size before budgeting.

Does the course include a copy of the standard?

Course inclusions vary by course and format. Confirm directly with ISOQAR Academy whether the applicable standard is included before enrolling — if not, budget separately for a current copy.

Is virtual training as effective as classroom training?

For foundation-level courses, live virtual formats generally work well. For auditor-level courses with hands-on practical exercises, in-person classroom formats offer more natural opportunities for group exercises, though live virtual delivery remains a reasonable option if travel cost or time away from the floor is the deciding factor.

Can one course cover ISO 9001, ISO 14001, and ISO 45001 together?

Yes — the IMS Internal Auditor course covers all three standards together for teams starting from scratch, and the CQI/IRCA conversion course extends an existing single-standard auditor’s skills to add the other two. Either route is typically more efficient than three separate single-standard courses for shops pursuing or maintaining an integrated management system — which one fits depends on whether your team already holds a single-standard auditor qualification.

Is ISOQAR Academy the same as ISOQAR certification?

No. ISOQAR Academy is the training division; ISOQAR’s certification division conducts the third-party audits that result in your certificate. They’re related parts of the same company but function as separate engagements with separate scopes and pricing.


📥 Free Resources

  • ISO 9001 Roadmap — Step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — Practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — Evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts

Not Sure What to Do Next?

🔹 Still researching whether formal training makes sense for your shop? Start with the ISO 9001 Roadmap to see exactly where your QMS stands before you commit a training budget.

🔹 Ready to look at course options? Review ISOQAR Academy’s current ISO 9001, 14001, and 45001 training courses and request a quote for your team size.

🔹 Want to compare against another training provider first? Compare BSI Group’s ISO training courses.

🔹 Still deciding on a certification body altogether? See how the major players stack up in Best ISO Certification Bodies — Ranked & Reviewed.


Training is one line item in a bigger certification budget, and it earns its cost once the rest of your QMS groundwork is in place — not before. Get the sequence right, and ISOQAR Academy training becomes the thing that builds real auditor competence on your team, not just a certificate on the wall.

The Standards Navigator covers ISO training, certification, and provider selection in plain, practitioner-level language — no sales pitch, just what actually moves the needle toward a compliant, audit-ready QMS.


Stay Ahead of Training and Certification Decisions

Most manufacturers who end up frustrated with a training investment aren’t dealing with a bad course — they’re dealing with a mismatch between the course level they booked and where their team actually stood.

Organizations that build their QMS, develop competence, and conduct meaningful internal audits before certification tend to walk into the certification process with fewer surprises than shops that bolt on training as an afterthought once a customer starts asking questions.

The Standards Navigator covers ISO training providers, certification body selection, and QMS implementation for manufacturers building a compliant, audit-ready quality system.

👉 Get updates on training provider comparisons and certification body reviews

👉 Be first to access new gap assessment tools and implementation resources

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

MDSAP vs ISO 13485: What’s the Difference and Do You Need Both in 2026?

MDSAP and ISO 13485 are often confused, but they answer different questions. This guide breaks down how the MDSAP audit program relates to the ISO 13485:2016 standard, what changed with FDA’s 2026 QMSR, and which manufacturers actually need MDSAP registration.

Whether the MDSAP consolidated audit program adds real value to your QMS — or scope you don’t need yet.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Two Audits, One QMS Standard — and a Decision Most Manufacturers Get Wrong

MDSAP vs ISO 13485 is a distinction worth getting right before you scope an audit program: these are not competing options, and they are not two paths to the same certificate. Treating them as interchangeable is exactly how manufacturers end up either over-auditing themselves or discovering — mid-application — that a market they assumed was covered isn’t.

If you sell into more than one of the five MDSAP countries, this decision affects your audit calendar, your registrar spend, and your regulatory submission timeline for years. If you sell only into the EU or UK, most of what follows doesn’t apply to you at all — and that’s worth knowing before you spend a quarter evaluating a program you don’t need.

This guide breaks down exactly what MDSAP is, how it relates to ISO 13485:2016, and — now that the FDA’s Quality Management System Regulation has replaced the legacy 21 CFR Part 820 — what changed for US-market manufacturers in 2026.

From the Floor: With 25+ years in heavy industrial manufacturing and a certified ISO 9001 Internal Auditor credential, I’ve seen the same regulated-QMS failure pattern show up regardless of which standard is on the cover — 9001 or 13485. It’s not missing documentation. It’s documentation that exists but doesn’t connect: a CAPA log that references a nonconformance report that was never actually closed out in the corrective action file. Stack five regulatory authorities’ expectations on top of each other instead of one, and that gap can become a nonconformity that appears in the MDSAP audit record used by the participating Regulatory Authorities.

Before you evaluate MDSAP, confirm your QMS actually conforms to ISO 13485:2016 first — MDSAP audits against it, it doesn’t substitute for it. Run the free ISO 13485 Gap Assessment Checklist and see exactly where your documentation stands before you add audit scope on top of it.

In This Guide

  • What MDSAP actually is, and how it relates to ISO 13485:2016
  • A side-by-side comparison of both frameworks
  • What changed in 2026 with the FDA’s QMSR and the revised MDSAP Audit Approach
  • Decision-stage signals for whether MDSAP applies to your business
  • What MDSAP costs — and what it saves — compared to separate country audits
  • Documentation issues that can create problems in MDSAP-scope audits
  • A readiness checklist and answers to the questions manufacturers ask most


👉 Start Here (Top Resources)

  • Own the standard MDSAP is built on: ISO 13485:2016 — ANSI Webstore — the foundation document every MDSAP audit is measured against. Use code CC2026 for 5% off through December 31, 2026.
  • Close documentation gaps before you’re audited on them: 9001Simplified — documentation kits built for manufacturers assembling or tightening a QMS without hiring a full-time consultant.
  • Get your team trained on the underlying requirements: ISO 13485 Training — BSI Group — BSI is one of the Auditing Organizations recognized under MDSAP, and their training builds the ISO 13485 foundation your audit is scored against.

What Is ISO 13485, and What Is MDSAP Built on Top Of It?

ISO 13485:2016 is the quality management system standard for medical device manufacturers. It’s a standalone document you can certify to on its own — covered in detail in our What Is ISO 13485 guide.

MDSAP (Medical Device Single Audit Program) is not a standard. It’s a regulatory audit program. Five participating Regulatory Authorities — Australia’s TGA, Brazil’s ANVISA, Health Canada, Japan’s MHLW/PMDA, and the U.S. FDA — use a single consolidated audit, conducted by an MDSAP-recognized Auditing Organization, to assess the applicable QMS and regulatory requirements across participating markets, rather than requiring separate audits from each regulator. That audit is scored against ISO 13485:2016 as the baseline, with country-specific regulatory requirements layered on top for each market a manufacturer participates in.

Standalone ISO 13485 certification, by contrast, is issued by certification bodies accredited through national accreditation bodies — in the US, that’s typically ANAB. MDSAP Auditing Organizations go through a separate recognition process run directly by the participating Regulatory Authorities, not through the standard accreditation pathway.

In plain terms: ISO 13485 is what you’re audited against. MDSAP is who accepts that audit, and how many regulators it satisfies at once.


Quick Answer

QuestionQuick Answer
Is MDSAP the same as ISO 13485?No. MDSAP is a multi-country regulatory audit program built on top of ISO 13485:2016 — it doesn’t replace the standard, it audits against it plus country-specific requirements.
Do I need ISO 13485 certification before MDSAP?No. Your QMS must conform to ISO 13485:2016, but you don’t necessarily need a separate ISO 13485 certificate before undergoing an MDSAP audit — the MDSAP audit itself assesses that conformance.
Is MDSAP required?Only for Class II–IV Canadian market access. In the other participating MDSAP markets, participation is generally voluntary, although it can consolidate applicable regulatory assessments across multiple markets.
Does MDSAP replace FDA inspections entirely?No. MDSAP audit results can be used by FDA within its regulatory program, but FDA retains its authority to conduct inspections, including for-cause inspections.

MDSAP vs ISO 13485: Side-by-Side

CategoryISO 13485:2016MDSAP
What it isA quality management system standardA multi-jurisdiction regulatory audit program
BasisStandalone documentBuilt on ISO 13485:2016 plus country-specific regulatory requirements
Who administers itCertification bodies accredited by ANAB or an equivalent accreditation bodyAuditing Organizations recognized by the five participating Regulatory Authorities
Countries coveredGlobal — recognized wherever ISO 13485 certification is acceptedAustralia, Brazil, Canada, Japan, United States
Can you buy it?Yes — it’s a purchasable standard documentNo — it’s an audit program, not a document
Mandatory?Often required by customers, notified bodies, or regulators (EU MDR, for example)Mandatory only for Class II–IV Canadian market access; voluntary elsewhere
Audit frequencyPer your certification body’s surveillance schedule — typically annualInitial audit followed by annual surveillance audits within the certification cycle
What you getAn ISO 13485 certificateAn MDSAP certification document and audit report each participating Regulatory Authority can use within its own regulatory program

For the broader question of how ISO 13485 stacks up against the standard most manufacturers compare it to first, see ISO 9001 vs ISO 13485.


The 2026 Regulatory Shift: QMSR and the Revised MDSAP Audit Approach

MDSAP vs ISO 13485 infographic showing the 2026 FDA QMSR transition and changes to medical device quality records
MDSAP vs ISO 13485: The 2026 FDA QMSR aligns U.S. medical device quality requirements with ISO 13485:2016 and changes FDA access to management review, internal audit, and supplier audit records.

Two changes landed in 2026 that directly affect this comparison.

On February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) officially took effect, replacing the legacy 21 CFR Part 820 Quality System Regulation and incorporating ISO 13485:2016 by reference. That doesn’t make US manufacturers MDSAP-compliant automatically — it means the US regulatory baseline now speaks the same structural language as ISO 13485, closing a gap that used to require manufacturers to maintain two separate documentation logics. We cover the mechanics of that shift in FDA QSR vs ISO 13485.

The QMSR also removed a long-standing FDA inspection exemption. Under the prior QSR, §820.180(c) shielded management review records, internal quality audit reports, and supplier audit reports from routine FDA inspection. The QMSR eliminates that exemption entirely — FDA’s own QMSR FAQ confirms investigators now have authority to review management review, quality audit, and supplier audit records as part of a standard inspection. For manufacturers who treated those records as internal-only, that’s a meaningful shift in what “audit-ready” documentation needs to look like.

Around the same window, the MDSAP Regulatory Authority Council released a revised Audit Approach document (MDSAP AU P0002.010), updating the audit sequence and process guidance auditors use during MDSAP assessments. If your last MDSAP audit was conducted under the prior version, don’t assume your documentation package is still current against the revised approach — verify against the current edition before your next audit window.

It can be tempting to assume that QMSR compliance automatically covers MDSAP scope. It doesn’t — QMSR alignment closes the gap between the US baseline and ISO 13485, but MDSAP still layers the applicable regulatory requirements of each participating jurisdiction on top of that baseline. Check where your QMS actually stands before you assume you’re covered → Run the ISO 13485 Gap Assessment Checklist.


Do You Need MDSAP? Decision-Stage Signals

  • If you are selling only into the EU or UK → you still need to meet the applicable medical-device QMS and conformity-assessment requirements for those markets, but MDSAP is not generally required there.
  • If you are selling into Canada at Class II, III, or IV → MDSAP is mandatory. Health Canada requires an MDSAP certificate, issued by a recognized MDSAP Auditing Organization, as part of the device license application.
  • If you sell into several of the five MDSAP countries → compare the cost and disruption of MDSAP against the separate regulatory assessments that would otherwise apply. Three or more can be a useful practical threshold for comparison, but the right number depends on your specific audit costs, inspection history, device scope, and market plans.
  • If you are already ISO 13485 certified and sell only into the US → weigh MDSAP against your actual FDA inspection frequency and any near-term expansion plans before adding audit scope you may not need yet.
MDSAP decision flowchart showing when medical device manufacturers need MDSAP for Canada and when it is generally voluntary in other markets
A practical MDSAP decision guide showing when certification is required for Canadian Class II–IV devices and when manufacturers should evaluate MDSAP based on market scope, audit costs, and regulatory strategy.

What MDSAP Actually Costs You — And What It Saves

The most common objection we hear is straightforward: MDSAP audits cost more than a standard ISO 13485 surveillance audit, so why add the expense?

That’s true in isolation — an MDSAP audit typically runs longer and costs more per audit day than a single-standard ISO 13485 surveillance visit, because the auditor is assessing conformance to multiple regulatory frameworks in one visit. But the comparison that matters isn’t MDSAP audit cost versus ISO 13485 audit cost. It’s MDSAP audit cost versus the combined cost of separate inspections from Health Canada, ANVISA, TGA, and PMDA, run independently, on different schedules, each requiring separate audit prep. For manufacturers selling across several MDSAP markets, the consolidation can make the overall audit program less costly and less disruptive than managing multiple separate regulatory assessments — but the business case depends on device classification, facility count, audit scope, your Auditing Organization, and your existing inspection cadence, so get a scoped quote rather than budgeting off a generic number.

Manufacturers building out documentation to support a broader audit scope shouldn’t be doing it from scratch. If your QMS documentation isn’t structured to hold up under multiple regulatory frameworks at once, that’s the gap to close first → 9001Simplified’s documentation kits are built for exactly this kind of consolidation work.


Documentation Issues That Can Create Problems in MDSAP Readiness

One area worth checking closely is CAPA traceability. CAPA records should connect clearly to the underlying nonconformance, investigation, corrective action, and effectiveness evidence, rather than leaving the auditor to reconcile separate systems manually — see our breakdown of common mistakes in ISO 13485 QMS implementation and the full CAPA requirements under ISO 13485 for what auditors expect to see connected.

Another area to review is how regulatory requirements are mapped into the QMS. MDSAP audits ISO 13485 alongside applicable jurisdiction-specific requirements, so documentation that only reflects one regulator’s language may need additional mapping before an MDSAP audit. Our guide on ISO 13485 documentation requirements covers how to structure it correctly the first time.


MDSAP vs ISO 13485 readiness infographic showing CAPA traceability, document control, regulatory mapping, internal audits, and audit evidence
MDSAP vs ISO 13485: MDSAP readiness depends on connected evidence across CAPA, document control, regulatory mapping, internal audits, and market scope.

MDSAP Readiness Checklist

✅ QMS is currently certified — or verified compliant — to ISO 13485:2016
✅ CAPA records cross-reference nonconformance reports within the QMS itself, not a separate tracking tool
✅ Document control system is organized by ISO 13485 clause structure, not by individual regulator language
✅ You’ve confirmed which of the five MDSAP countries you actually sell into or plan to
✅ You’ve reviewed your documentation against the revised MDSAP Audit Approach (AU P0002.010)
✅ You’ve scoped audit cost and timeline with an MDSAP-recognized Auditing Organization
✅ Internal audit process already traces process interactions, not just individual clause compliance — see how to audit a medical device QMS


Frequently Asked Questions

Is MDSAP the same thing as ISO 13485?

No. ISO 13485:2016 is the quality management system standard. MDSAP is a regulatory audit program that assesses conformance to that standard, plus country-specific requirements from five participating Regulatory Authorities, in a single consolidated audit.

Do I need to be ISO 13485 certified before I can apply for MDSAP?

Your QMS needs to conform to ISO 13485:2016 — MDSAP auditors assess that conformance directly as part of the MDSAP audit itself. In practice, most manufacturers already hold or are pursuing ISO 13485 certification before entering the MDSAP process.

Which countries does MDSAP cover?

Five participating Regulatory Authorities: Australia (TGA), Brazil (ANVISA), Canada (Health Canada), Japan (MHLW/PMDA), and the United States (FDA). A number of other regulators participate as observers or affiliate members without full recognition of MDSAP audit results.

Is MDSAP required to sell medical devices in the United States?

No. The FDA accepts MDSAP audit results as part of its compliance program, and the 2026 QMSR incorporates ISO 13485:2016 by reference, but MDSAP participation itself remains voluntary for US-only manufacturers.

How did the FDA’s 2026 QMSR change affect MDSAP?

The QMSR, effective February 2, 2026, replaced 21 CFR Part 820 and incorporated ISO 13485:2016 by reference — narrowing the gap between US regulatory expectations and the ISO 13485 baseline that MDSAP already audits against. It doesn’t grant automatic MDSAP compliance; it changes what the US regulatory floor requires your documentation to look like.

How much does an MDSAP audit cost compared to a standard ISO 13485 audit?

MDSAP audits generally run longer and cost more per audit than a single-standard ISO 13485 surveillance audit, since the scope covers multiple regulatory frameworks in one visit. Pricing varies significantly by Auditing Organization, facility count, and audit scope — get a quote scoped to your specific situation rather than relying on a general figure.

Can a small manufacturer participate in MDSAP?

Yes. Any manufacturer with a product that falls under the scope of at least one participating Regulatory Authority may apply. It tends to make the most financial sense for manufacturers selling into several of the five MDSAP countries, where consolidating audits can produce clearer savings — though the exact threshold depends on your specific cost structure.

Does an MDSAP certificate replace my ISO 13485 certificate?

Not automatically, and it depends on the market. In Canada, the MDSAP certificate has replaced the standalone ISO 13485 certificate in the device license application process for Class II–IV devices. In most other participating markets, manufacturers typically maintain both, since ISO 13485 certification is often required independently by customers or notified bodies.


📥 Free Resources

  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements before pursuing MDSAP or standalone certification.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification.

Not Sure What to Do Next?

🔹 Still researching whether MDSAP applies to you? Start with the ISO 13485 Gap Assessment Checklist — confirm your QMS conforms to ISO 13485:2016 before you evaluate adding MDSAP scope on top of it.

🔹 Ready to close documentation gaps before your next audit? 9001Simplified’s documentation kits are built for manufacturers structuring a QMS to hold up under more than one regulatory framework at once.

🔹 Need to buy the ISO 13485:2016 standard itself? Get it directly from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026.

🔹 Want your team trained on the requirements before your MDSAP audit? BSI Group’s ISO 13485 training builds the foundation MDSAP auditors score against.

MDSAP isn’t a bigger version of ISO 13485 certification — it’s a different question entirely: not “is your QMS compliant,” but “how many regulators can rely on the same answer.” Get that distinction right before you scope an audit program you may not need, or miss one you do. The Standards Navigator will keep tracking how MDSAP and the 2026 QMSR shift continue to interact as more guidance comes out.


Stay Ahead of the Next Regulatory Shift

Manufacturers who treat MDSAP as “extra paperwork” usually find out the hard way — mid-application, with a Canadian import deadline already on the calendar. Manufacturers who map their audit scope to their actual markets first spend less on audits and never scramble for a certificate they didn’t know they’d need.

The Standards Navigator tracks how ISO 13485, MDSAP, and FDA’s QMSR continue to shift against each other so you don’t have to monitor five regulators’ guidance pages yourself.

👉 Get updates on medical device compliance and regulatory changes as they happen
👉 Be first to access new gap assessment tools and documentation resources as we build them

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

AS9100 Internal Audit Process: A Step-by-Step Guide for 2026

AS9100 Clause 9.2 requires more than an ISO 9001 internal audit program — customer and regulatory requirements have to be built into your audit criteria, and results have to reach management. This guide breaks down the six-part audit workflow, what a real internal audit checklist should cover, how findings feed into management review and AS9101 reporting, and the objectivity gap that trips up small aerospace quality teams.

How aerospace suppliers plan, conduct, and close out a Clause 9.2-compliant internal audit program

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your Internal Audit Program Is What Helps Keep Your AS9100 Certification Credible

An AS9100 certificate doesn’t prove your QMS is working. Your AS9100 internal audit process helps prove that it is.

Most operations managers treat internal audits as a compliance formality — something to schedule before the registrar shows up, not something that actually finds problems. That approach works right up until a surveillance audit surfaces a nonconformance your own internal audit should have caught six months earlier. At that point, the registrar isn’t just questioning the finding. They’re questioning whether your internal audit program is real.

If you’re already certified and running audits on autopilot, or preparing for your first AS9100 certification and building this process from scratch, the standard is specific about what “real” looks like. Clause 9.2 lays out exactly what your internal audit program has to prove, and AS9100 Rev D adds requirements ISO 9001 doesn’t have.

From the Floor: I’ve sat in gap assessment meetings where the documented internal audit schedule looked airtight on paper — every process, every quarter, neatly assigned. Then you pull the actual audit records and half of them are checklist walk-throughs with no objective evidence attached, no findings, no closure dates. An auditor doesn’t need long to spot the difference between an internal audit program that’s running and one that’s just being logged.

👉 Before you build or rebuild your internal audit program, run the AS9100 Rev D Gap Assessment Checklist — a 74-item, clause-by-clause tool that shows you exactly where your current audit coverage has gaps before an external auditor finds them for you.


In This Guide

  • What Clause 9.2 actually requires, and where AS9100 goes beyond ISO 9001
  • The six-step internal audit process defined in Clause 9.2.2
  • How internal audit findings feed into management review and AS9101 reporting
  • A ready-to-use internal audit checklist structure
  • Common mistakes that turn a real audit program into a paperwork exercise
  • Where to buy the standard and where to get trained on running compliant audits


👉 Start Here (Top Resources)

  • AS9100D — ANSI Webstore — the current edition of the standard, including the exact Clause 9.2 language your audit program has to satisfy. Use coupon code CC2026 for 5% off through December 31, 2026.
  • ISO 19011:2018 — ANSI Webstore — the audit guidelines standard referenced directly by AS9100 internal audit resources; worth owning if you’re training internal auditors.
  • AS9100 Training — BSI Group — for teams that need to formally qualify internal auditors on AS9100-specific requirements, not just general ISO 9001 audit technique.

What Clause 9.2 Actually Requires

Clause 9.2.1 requires you to conduct internal audits at planned intervals to determine whether your quality management system conforms to three things: your own organization’s requirements, the AS9100 standard itself, and the QMS is effectively implemented and maintained. That’s the ISO 9001 baseline.

AS9100 Rev D builds directly on that clause text. Under the standard’s Annex L structure, the aerospace-specific language is written straight into Clause 9.2.1 itself: your organization’s requirements for internal audit purposes must explicitly include customer requirements and applicable statutory and regulatory requirements — not just your internal procedures. That’s not guidance layered on top of ISO 9001; it’s part of the clause language you’re audited against. Audit results also have to be reported to relevant management, not just filed.

Most common finding: Internal audit programs that check ISO 9001 conformance thoroughly but never verify against a specific customer’s flow-down requirements or purchase order quality clauses. That’s a Clause 9.2 gap I commonly see when aerospace suppliers transition from ISO 9001 to AS9100.

ISO 9001 Baseline (Clause 9.2)Aerospace-Specific Clause 9.2 Language (Annex L Addition)
Conformance to the organization’s own QMS requirementsMust explicitly include customer, statutory, and regulatory requirements
Conformance to the standardAS9100 Rev D requirements, including its aerospace-specific additions
Effective implementation and maintenanceResults must be reported to relevant management, feeding directly into management review

If you are preparing for your first AS9100 certification → build your audit criteria around customer and regulatory requirements from day one, not as an afterthought once ISO 9001 conformance is handled.

👉 Need to see the exact Clause 9.2 language for yourself before you build your audit program around it? Get the current AS9100D edition from the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.


The AS9100 Internal Audit Process: A Six-Part Workflow Built From Clause 9.2.2

AS9100 audit program showing risk-based planning, audit frequency, previous findings, and an annual internal audit schedule in an aerospace manufacturing facility
A risk-based AS9100 audit program considers process importance, changes, previous findings, and risk when establishing the internal audit schedule.

Clause 9.2.2 lays out the requirements your audit program has to satisfy — the audit program itself, planning and conduct, auditor objectivity, reporting, corrective action, and retained documented information. Read together, that maps cleanly onto six practical steps, and an auditor will ask about all six.

1. Audit Program

Establish, implement, and maintain an audit program that identifies frequency, methods, responsibilities, planning requirements, and reporting. This has to account for the importance of the processes involved, changes affecting your organization, and the results of previous audits — not a static calendar you set once and never revisit.

2. Audit Criteria and Scope

Define what standard, procedure, or requirement each audit is measured against, and how far that audit reaches — which processes, which shifts, which locations if you run more than one facility.

3. Auditor Selection

Select auditors and conduct audits in a way that ensures objectivity and impartiality. Nobody audits their own work. On a small quality team this is often the hardest requirement to satisfy on paper — it usually means cross-training auditors across departments so a floor supervisor never audits the process they run.

4. Reporting Results

Audit results go to relevant management — not just the quality manager’s file. If a finding touches production scheduling, engineering, or purchasing, that function’s management needs visibility into it.

5. Corrective Action

Take appropriate correction and corrective action without undue delay when nonconformities are found. “Without undue delay” is intentionally vague in the standard, but in practice, your corrective action process should establish a documented target closure date appropriate to the severity of the finding — an open-ended promise to “look into it” won’t hold up as objective evidence of an effective process.

6. Retained Documentation

Keep documented information as evidence of the audit program’s implementation and the audit results. These are among the first records an external auditor is likely to examine: not your procedure, but your actual audit records — schedules, checklists, findings, objective evidence, and closure dates.

👉 If your audit records are more calendar than evidence, that’s the gap that surfaces during a surveillance audit — not a certification audit. Run the gap assessment checklist against your current program before your next registrar visit, not after.

AS9100 internal auditor reviewing work instructions, actual work, inspection records, and objective evidence on an aerospace manufacturing floor
An effective AS9100 internal audit follows the evidence from documented procedures to actual work, inspection records, and process effectiveness.

What Should an AS9100 Internal Audit Checklist Include?

A checklist built only around ISO 9001 clause conformance misses the aerospace-specific scope Clause 9.2.1 actually requires. Use this as the framework for what each internal audit needs to cover:

Audit AreaWhat the Auditor Should Verify
Process requirementsApplicable AS9100 clauses and internal procedure requirements
Customer requirementsPurchase order and contract flow-down requirements
Regulatory requirementsApplicable statutory and regulatory obligations
Objective evidenceActual records and direct observations, not verbal confirmation
Process effectivenessWhether the process is achieving its intended result, not just running
FindingsNonconformities clearly supported by objective evidence
Corrective actionRoot cause analysis, corrective action, and verification of effectiveness
Follow-upClosure evidence and confirmation the fix actually worked

If your operation also carries program-specific deliverables under AS9145 (APQP and PPAP), extend your audit criteria to those documents too — see AS9145 Explained for what’s typically in scope. And if any of your special processes are already covered under NADCAP, coordinate your internal audit scope so you’re not duplicating external oversight — NADCAP vs AS9100 breaks down where the two programs overlap and where they don’t.

AS9100 corrective action workflow showing audit finding, containment, root cause analysis, corrective action, effectiveness verification, and closure
An AS9100 corrective action is not complete until the organization verifies that the action worked and documents the results.

How Internal Audit Results Feed Into Management Review

Internal audit findings aren’t the end of the process — Clause 9.3 requires them as an input into management review. Corrective actions from internal audits, along with trending data like recurring nonconformities, similar issues across multiple processes, and top process concerns, should show up as agenda items top management actually discusses. That requirement comes from your QMS’s management review clause, not from any external audit form.

Separately, when your registrar conducts your certification or surveillance audit, results get documented on AS9101 — the standardized audit report form referenced by SAE International and logged in the IAQG OASIS database. AS9101 doesn’t dictate what your internal management review has to look like. But an external auditor completing that form will ask to see your management review minutes, and if internal audit trends never make it into those minutes, that gap is easy to spot — not because AS9101 requires a specific format, but because the disconnect itself signals the management review process isn’t functioning as intended.

If you are already ISO 9001 certified and adding AS9100 → your internal audit process likely doesn’t need to change structurally. What changes is audit criteria — you now have to audit against customer and regulatory requirements your ISO 9001 program never had to touch, and management review needs a direct line from audit findings to those aerospace-specific requirements.


Objection: “We Don’t Have Staff to Audit Objectively”

This is the most common pushback on small aerospace shops — a 15-person quality team can’t realistically avoid people auditing processes adjacent to their own work.

It’s a real constraint, but it’s manageable without adding headcount. Cross-train two or three people across departments so each can audit outside their own process. A machinist trained as an internal auditor can objectively audit the receiving inspection process; the receiving inspector can objectively audit machining documentation. Registrars don’t require a dedicated audit department — they require evidence that whoever conducted the audit had no stake in the outcome. Document that logic in your audit program procedure, and it holds up.


Quick Internal Audit Readiness Checklist

✅ Audit program covers all applicable processes at a frequency justified by risk and past findings

✅ Audit criteria explicitly reference customer purchase order requirements, not just internal procedures

✅ Auditors are demonstrably independent of the process they’re auditing

✅ Findings include objective evidence — not just a pass/fail checkbox

✅ Corrective actions have documented target closure dates

✅ Audit results appear as a distinct agenda item in management review minutes

⚠️ If any of these are missing, that’s the gap a registrar finds before you do


Frequently Asked Questions

What does Clause 9.2 of AS9100 actually require?

Clause 9.2 requires organizations to run internal audits at planned intervals to confirm the QMS conforms to the organization’s own requirements — which under AS9100 must include customer, statutory, and regulatory requirements — conforms to the AS9100 standard itself, and is effectively implemented. Results must be reported to relevant management.

How often do AS9100 internal audits need to happen?

The standard doesn’t set a fixed interval. Frequency has to be justified by the importance of the process, the results of previous audits, and any changes affecting the organization. Higher-risk processes — special processes, product safety-critical operations — typically warrant more frequent audits than lower-risk administrative processes.

Can one person run the entire internal audit program on a small team?

Generally, yes, as long as objectivity is maintained. The requirement is independence from the process being audited, not a minimum team size. On very small teams this can require creative scheduling or occasionally bringing in an outside auditor for processes where no internal person can honestly claim independence.

Do internal audit findings have to be reported to the registrar?

No. Internal audit results are reported to your own relevant management, not to the certification body. The registrar reviews your internal audit records and evidence of corrective action during surveillance and recertification audits — they don’t need real-time reporting.

What’s the difference between an internal audit and the AS9101 certification audit?

Your internal audit program is something you run yourselves, on your own schedule, against your own and the standard’s requirements. AS9101 is the standardized form your registrar uses to document the results of your external certification and surveillance audits, which then get logged in the IAQG OASIS database. A strong internal audit program is largely what prepares you to pass the AS9101-documented external audit cleanly.

Can internal audits be conducted remotely?

The standard doesn’t prohibit it, and many quality teams do conduct document reviews and some process audits remotely. Physical, in-person audits are still strongly preferred for shop floor processes where objective evidence — traveler stamps, calibration tags, first article records — needs to be directly observed rather than described.

What happens if our internal audit program has gaps when the registrar shows up?

It depends on severity and pattern, and classification is ultimately the auditor’s call based on the evidence in front of them. An isolated missed audit interval on a low-risk process may be treated differently from a persistent systemic failure, depending on the evidence and the auditor’s assessment. A pattern of audits with no objective evidence, no findings ever recorded, or no connection to management review calls into question whether the QMS’s self-monitoring is functioning at all — which is the kind of gap that tends to draw closer scrutiny.

Is a documented procedure enough, or do we need to prove the audits actually happened?

A procedure alone isn’t enough. Registrars expect to see the records: audit schedules, completed checklists with objective evidence, documented findings, and closure evidence for corrective actions. The procedure describes what you’re supposed to do — the records prove you did it.


📥 Free Resources

  • AS9100 Rev D Gap Assessment Checklist — 74-item, clause-by-clause checklist for aerospace suppliers assessing their QMS, including internal audit coverage, before certification.
  • ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

Not Sure What to Do Next?

🔹 Still researching what AS9100 internal audits require? Start with the What Is AS9100? pillar guide, then read AS9100 vs ISO 9001 to see exactly which requirements are new to you if you’re already ISO 9001 certified.

🔹 Ready to build or fix your internal audit program? Run the AS9100 Rev D Gap Assessment Checklist against your current audit records, then check the AS9100 Implementation Timeline to see where audit program maturity fits into your certification schedule.

🔹 Need to buy the standard or get auditors trained? Get the current edition from the ANSI Webstore with code CC2026 for 5% off, and see AS9100 Certification Bodies: Ranked & Reviewed for AS9100 auditor training through BSI Group.


A weak internal audit program is one of the most common reasons a QMS that looks compliant on paper fails to hold up in front of a registrar. Build the six-step process the standard actually asks for, put real objective evidence behind every audit, and your surveillance audits stop being a surprise. That’s what The Standards Navigator’s AS9100 coverage is built around — the requirements as they’re actually enforced, not just as they’re written.


Before You Go

Most aerospace suppliers don’t lose points on AS9100 audits because they misunderstand Clause 9.2 — they lose points because their internal audit program looks good on paper and falls apart under objective evidence review.

Shops that treat internal audits as a real management tool catch their own nonconformances before a registrar does. Shops that treat them as a scheduling formality find out the hard way, usually during a surveillance audit, that “completed” and “effective” aren’t the same thing.

The Standards Navigator covers the AS9100 requirements aerospace suppliers actually get audited against — not just the clause text, but how registrars interpret it in practice.

👉 Get updates on AS9100 implementation and internal audit best practices

👉 Be first to access new aerospace gap assessment tools and checklists

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

AS9100 Certification Bodies: Ranked & Reviewed (2026)

Not every AS9100 certification body brings the same aerospace expertise to an audit. This guide breaks down what AS9100 accreditation actually requires, which certification bodies are active in the space, and the questions to ask before signing with a registrar.

Comparing accredited AS9100 registrars — what to look for, what to avoid, and which body fits your operation

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Choosing the Wrong Registrar Costs More Than the Audit

Not all AS9100 certification bodies operate the same way. Some assign a dedicated aerospace lead auditor who understands configuration management and counterfeit parts controls on sight. Others rotate generalist auditors who spend half of Stage 1 relearning your industry — and bill you for the education.

A certificate issued by an appropriately accredited certification body is intended to demonstrate conformity to the same AS9100 requirements, regardless of which body issues it. What can differ significantly is the accreditation scope, auditor expertise, scheduling, audit experience, customer acceptance, and overall certification experience. For a supplier chasing a Tier 1 customer deadline, that difference is real money and real risk.

If you’re comparing registrars for the first time, this guide breaks down what accreditation actually means, which bodies are active in the AS9100 space, and how to evaluate quotes so you’re not choosing on price alone. If you’re already certified and evaluating a switch, the sections on auditor consistency and surveillance cadence will matter most to you.

From the floor: I’ve sat through registrar selection more than once at a heavy industrial manufacturing operation — comparing quotes side by side, all technically accredited, all wildly different in price and turnaround. The number that mattered wasn’t the quote total. It was how the registrar answered questions about auditor aerospace experience, how they’d handle surveillance-audit continuity year over year, and what their process looked like if a Stage 2 audit turned up a major finding. One bidder had clearly never audited anything with configuration management or counterfeit-parts controls in scope, and it showed the moment we started asking specifics. That’s the conversation that should happen before you sign, not the one that happens after your first nonconformance over something your auditor didn’t understand.

Before you request quotes, run a clause-by-clause gap check. Most organizations don’t get burned by picking the wrong registrar — they get burned by walking into Stage 1 not knowing where their gaps are. → AS9100 Rev D Gap Assessment Checklist — 74 items, clause-by-clause, built for aerospace suppliers preparing for certification.


In This Guide

  • What AS9100 accreditation actually requires
  • How to verify a registrar is legitimately accredited
  • What separates a good aerospace auditor from a generalist
  • How these certification bodies were evaluated, and which fit different supplier profiles
  • Questions to ask before signing a registrar contract
  • Cost and timeline expectations by registrar type
  • What to do after you select a certification body


👉 Start Here (Top Resources)

👉 Get the official AS9100 Rev D standard before you approach any registrar → AS9100 / SAE Standards — ANSI Webstore

👉 Get your team trained on AS9100 requirements ahead of Stage 1 → BSI Group AS9100 Training

👉 Run a clause-by-clause gap check before requesting quotes → AS9100 Rev D Gap Assessment Checklist


What Does AS9100 Accreditation Actually Mean?

AS9100 certification isn’t something any registrar can simply decide to offer. Certification bodies (also called registrars or CBs) must hold appropriate accreditation and scope to issue an accredited AS9100 certificate — meaning an independent accreditation body has verified the CB is competent to audit against the standard.

For AS9100 specifically, that accreditation runs through a recognized national accreditation body — in the U.S., ANAB accredits more AS9100 certification bodies than any other accreditation body, though it isn’t the only IAF-recognized option (IAS is also recognized). Accreditation is evaluated against ISO/IEC 17021-1 plus the aerospace-specific IAQG 9104-series requirements developed by the International Aerospace Quality Group (IAQG). Holding ISO 9001 accreditation does not automatically mean a certification body also holds AS9100 accreditation — the two are evaluated and scoped separately, and a registrar without current AS9100 accreditation scope cannot issue an accredited AS9100 certificate that meets the applicable certification-scheme requirements, regardless of how experienced their auditors sound on a sales call.

This matters because a certificate from a body without properly scoped accreditation isn’t just a paperwork issue — it may not satisfy your customer’s supplier-qualification requirements, potentially costing you both certification time and audit expense.

For background on what the standard itself requires before you get to registrar selection, see What Is AS9100? and AS9100 vs ISO 9001.


How to Verify a Registrar Is Legitimately Accredited

Don’t take a sales rep’s word for current AS9100 scope. Verify it directly:

1. Check the OASIS database. The IAQG OASIS Certified Supplier Directory is the official record of AS9100-certified organizations and the certification bodies that issued their certificates. If a registrar’s certifications aren’t showing up in OASIS, that’s a serious red flag.

2. Confirm current accreditation scope directly with the accreditation body. ANAB accredits more AS9100 certification bodies in the U.S. than any other accreditation body and publishes which certification bodies hold active accreditation and what scopes each one covers — some registrars are accredited for aerospace manufacturing but not for MRO (AS9110) or distribution (AS9120). If a registrar cites a different IAF-recognized accreditation body, confirm that body’s scope listing directly rather than assuming it’s equivalent to ANAB’s.

3. Ask what your accredited scope actually covers. Rather than asking whether a registrar covers a specific code, ask: “What is your current accredited AS9100 scope, and does it cover the activities, products, and industry sector included in my proposed certification scope?” Have the registrar confirm the applicable industry and technical scope classifications directly — don’t assume a single code number settles the question.

4. Ask for the accreditation certificate, not a logo on a website. A registrar’s marketing page listing “AS9100 Accredited” isn’t proof — request the actual accreditation certificate showing current scope and expiration.

⚠️ Most common finding: Suppliers under customer pressure sometimes select a registrar based on price and turnaround time alone, without confirming current AS9100 scope in detail — then discover during Stage 2 that a scope gap means the certificate won’t satisfy their customer’s supplier requirements.


What Separates a Good Aerospace Auditor From a Generalist

AS9100 certification bodies review with an auditor examining a first article inspection report beside a precision aerospace component
Choosing the right AS9100 certification bodies means looking beyond the certificate to auditor experience and aerospace expertise.

AS9100 auditors need aerospace-specific fluency that a generalist ISO 9001 auditor may not have. This is the criteria worth keeping in mind as you read the comparisons below — it’s the difference that actually separates certification bodies in practice once you’ve confirmed that the appropriate accreditation and scope are in place. When evaluating a registrar, ask specifically about auditor experience in:

  • Configuration management — Clause 8.1.2’s requirements go well beyond typical ISO 9001 document control
  • Counterfeit parts prevention — Clause 8.1.4 requires audit-ready evidence most non-aerospace auditors have never evaluated
  • First article inspection (FAI) — auditors unfamiliar with the AS9102 forms published by SAE International will struggle to evaluate your FAI records meaningfully
  • Special processes and traceability — Clause 8.5.2 traceability requirements are more stringent than general manufacturing

If you are preparing for your first AS9100 certification → confirm the specific auditor assigned to your account has aerospace industry audit hours, not just AS9100 training credentials. Ask the registrar directly; reputable ones will tell you.

For a deeper look at the traceability and counterfeit-parts requirements auditors will actually test against, see AS9100 Traceability Requirements and AS9100 Counterfeit Parts Standards.


How These Certification Bodies Were Evaluated

Before comparing specific bodies, here’s the criteria behind the categories below:

  • AS9100 accreditation status and scope
  • Aerospace auditor availability and depth of aerospace-specific experience
  • Geographic coverage and multi-site capability
  • Ability to combine AS9100 audits with ISO 9001, ISO 14001, or other management-system audits
  • Fit for different supplier types — manufacturers, MRO organizations, distributors
  • Scheduling flexibility and certification-cycle support

These are editorial recommendations based on accreditation scope, aerospace specialization, geographic coverage, multi-standard capability, and fit for different supplier profiles — not customer satisfaction scores, audit outcome data, or any undisclosed commercial relationship. Always verify current accreditation status yourself through OASIS and ANAB before requesting quotes.


AS9100 Certification Bodies Worth Comparing

The six bodies below are established, accredited names in aerospace quality certification worth including in your quote comparison — not a claim that they’re the only six, or objectively the “best” six, available. Dozens of ANAB-accredited bodies issue AS9100 certificates. Always verify current scope through OASIS before signing with any registrar.

If you already have a strong sense of which profile matches your operation → skip to that category below rather than reading all six in order.

AS9100 certification bodies compared by aerospace focus, multi-site operations, manufacturing, and industrial certification needs
AS9100 certification bodies serve different operational needs, from aerospace-focused suppliers and multi-site operations to combined industrial certification.

Best Overall for Multi-Standard Aerospace Suppliers: BSI Group

Why I’d consider them: BSI certifies against a very wide range of standards — AS9100 alongside ISO 9001, AS9110, AS9120, ISO 14001, and most other major management-system standards. If your operation is pursuing more than one certification, or expects to add standards later, that breadth means fewer registrar relationships to manage over time. Ask specifically whether your account would be assigned one lead auditor across all standards or separate auditors per standard — that affects both cost and consistency.

Best for Aerospace-Focused Certification Experience: Perry Johnson Registrars (PJR)

Why I’d consider them: PJR maintains multiple international accreditations (ANAB, UKAS, JAB) and markets a dedicated aerospace audit staff. For a supplier whose top priority is an auditor who won’t need aerospace concepts explained from scratch, this is worth a direct conversation about auditor assignment. Ask for the assigned auditor’s aerospace sector history before you sign, not after.

Best for Manufacturers Entering Aerospace Supply Chains: NSF-ISR

Why I’d consider them: NSF-ISR has a strong general manufacturing and industrial certification presence. For a fabricator or machine shop pursuing AS9100 for the first time as a new aerospace supplier, a registrar with broad industrial-certification familiarity alongside aerospace scope can be a comfortable entry point. Ask how many first-time AS9100 clients they’ve certified in the past year — that experience matters more than tenure alone for a first certification.

Best for Global or Multi-Site Operations: DEKRA Certification

Why I’d consider them: DEKRA’s global reach and integrated auditing across multiple management-system standards make them worth considering for suppliers with international sites. If multi-site consistency is a priority, ask specifically how auditor assignment and certification scope will be coordinated across locations — that coordination is where multi-site certifications most often run into trouble.

Best for Defense and Marine-Adjacent Aerospace: ABS Quality Evaluations

Why I’d consider them: ABS has a long-standing presence in industrial and aerospace certification, with particular relevance for suppliers whose work overlaps defense or marine-adjacent aerospace segments. Ask directly whether their auditor pool has experience with your specific product category — defense-adjacent scope can carry additional documentation expectations worth confirming up front.

Best for Combined Aerospace and Industrial-Process Certification: DNV

Why I’d consider them: DNV brings deep process-industry audit experience alongside aerospace capability — a reasonable fit for suppliers whose certification needs span both aerospace and broader industrial processes. Ask whether a combined audit across your process and aerospace scopes is possible in a single visit, since that’s where DNV’s dual background can actually save audit days.

At a glance:

Best ForCertification Body
Multi-standard aerospace suppliersBSI Group
Aerospace-focused certification experiencePerry Johnson Registrars (PJR)
Manufacturers entering aerospace supply chainsNSF-ISR
Global or multi-site operationsDEKRA Certification
Defense and marine-adjacent aerospaceABS Quality Evaluations
Combined aerospace and industrial-process certificationDNV

For training — as distinct from certification itself — BSI also offers AS9100-specific coursework covering requirements, internal auditing, and lead auditor preparation.

→ Auditors move faster through Stage 1 when your internal team already knows the standard cold: BSI Group AS9100 Training

For a broader comparison of certification bodies across ISO standards generally — not aerospace-specific — see Best ISO Certification Bodies.


Questions to Ask Before You Sign

Bring these ten questions into every registrar call:

✅ What is your current accredited scope for AS9100, and does it cover the activities, products, and industry sector included in my proposed certification scope? (For U.S. certification bodies, confirm the applicable scope through ANAB.)
✅ Who will be the lead auditor assigned to my account, and what aerospace sectors have they audited?
✅ Will the same auditor normally return for surveillance audits, or should I expect rotation?
✅ How many aerospace-specific audits has my assigned lead auditor conducted in the past 12 months?
✅ What is your typical Stage 1 to Stage 2 turnaround time, and what is the planned audit duration?
✅ What happens if my assigned auditor becomes unavailable close to the scheduled audit date?
✅ What is included in the quoted price — are travel expenses included or billed separately?
✅ What is your nonconformance grading criteria, and what happens if Stage 2 produces a major finding?
✅ How are audit-day schedule changes typically handled?
✅ Can my certificate scope accommodate future expansion — additional sites, products, or standards?

AS9100 certification bodies comparison as an operations manager reviews registrar questions before signing
Compare AS9100 certification bodies carefully before signing, including accreditation, aerospace experience, audit approach, cost, and NCR handling.

If you are under customer pressure to certify quickly → prioritize registrars with confirmed availability in your timeframe over the lowest quote. A registrar that can’t schedule Stage 1 for four months doesn’t help you meet a customer deadline, regardless of price.


Cost and Timeline: What to Expect

These are planning ranges, not fixed market prices. Actual AS9100 certification fees depend on employee count, number of sites, audit complexity, applicable scope, operational complexity, shift structure, travel, audit days required, and whether other management systems are audited together.

FactorTypical Planning RangeNotes
Stage 1 + Stage 2 audit fees$8,000–$18,000Varies by facility size, employee count, and site complexity
Annual surveillance audits$3,000–$7,000 per yearRequired to maintain certification between three-year recertification cycles
Recertification audit$6,000–$12,000Every three years, comparable in scope to initial certification

Ask any registrar directly whether combining AS9100 with an existing ISO 9001 or ISO 14001 audit could reduce total audit days — this varies by registrar and by how your existing certifications are scheduled, so get it confirmed in your specific quote rather than assuming a standard discount applies.

On timeline: the 3–6 month range you’ll often hear for “registrar selection to certificate issuance” assumes your QMS is already substantially implemented and you’re simply at the registrar-selection and audit-scheduling stage. It is not a full AS9100 implementation timeline. If you’re starting without an existing QMS, expect considerably longer — see AS9100 Implementation Timeline for phase-by-phase ranges depending on your starting point.

For a full breakdown of certification costs beyond registrar fees — internal audit prep, documentation, and consulting — see How Much Does AS9100 Certification Cost?.


Common Mistakes When Selecting a Registrar

Choosing on price alone. The cheapest quote often reflects less aerospace-specific auditor experience, not efficiency. A registrar that costs more but assigns a dedicated aerospace lead auditor typically pays for itself in fewer findings and less audit-day confusion.

Not confirming scope in detail before signing. As covered above — AS9100 accreditation doesn’t automatically cover AS9110 (MRO) or AS9120 (distribution). If your business spans more than one, confirm scope for each. See AS9110 vs AS9120 if you’re uncertain which applies to your operation.

Assuming certification body and consultant can be the same entity. Certification bodies must maintain impartiality, and accredited certification activities are subject to strict rules governing consulting and conflicts of interest. A certification body should not be building the QMS it is then responsible for certifying. If a “certification body” is offering to build your documentation and then certify you, ask directly how that’s structured to avoid a conflict.

Ignoring auditor turnover history. Ask how long auditors typically stay assigned to accounts. Frequent auditor rotation means re-explaining your operation’s context every surveillance cycle.


What to Do After You Select a Certification Body

Step 1 — Confirm scope and schedule your Stage 1 readiness review. Most registrars offer an optional pre-assessment to catch major gaps before the audit clock starts.

Step 2 — Run your internal gap assessment first. Don’t walk into a pre-assessment blind. → AS9100 Rev D Gap Assessment Checklist

Step 3 — Address FAI, traceability, and counterfeit parts documentation early. These are the areas generalist QMS documentation most often misses. See First Article Inspection Requirements and FOD Control Standards.

Step 4 — Close the knowledge gap before Stage 1, not during it. An auditor testing your team on requirements they’ve never formally learned is one of the most avoidable sources of Stage 1 findings. → BSI Group AS9100 Training


FAQ

Can any ISO 9001 certification body also certify AS9100?

Not automatically. A registrar must hold separate, specific accreditation for AS9100 through ANAB (or an equivalent IAF-recognized accreditation body), evaluated against ISO/IEC 17021-1 plus the IAQG 9104-series requirements. ISO 9001 accreditation does not automatically extend to AS9100 — the two are scoped and evaluated separately.

How do I verify a certification body is actually accredited for AS9100?

Check the IAQG OASIS Certified Supplier Directory, which lists certified organizations and the registrars that issued their certificates, and confirm current scope directly with ANAB. Don’t rely solely on a registrar’s own marketing claims.

Is the cheapest registrar always the wrong choice?

Not automatically — but a significant price gap usually reflects a difference in auditor aerospace experience, scheduling flexibility, or accreditation scope. Compare quotes on auditor qualifications and turnaround time, not just the number.

Do I need a different registrar for AS9100, AS9110, and AS9120?

Not necessarily the same body, but you do need separate accreditation scope confirmed for each standard you’re certifying against, since they cover different operations — manufacturing, MRO, and distribution respectively. See AS9110 vs AS9120 for the distinction.

Can I switch certification bodies mid-cycle if I’m unhappy with my current one?

Yes, though timing matters — most organizations switch at their three-year recertification point rather than mid-cycle, since transferring an active certificate involves a transfer audit process. Talk to your prospective new registrar about transfer procedures before your current cycle ends.

Does a certification body also provide consulting or documentation help?

Generally, no — accredited certification bodies are subject to impartiality rules that treat consulting on your QMS documentation as a conflict of interest with certifying that same QMS. For documentation support, work with a separate consultant or a documentation kit, then bring an independent registrar in for certification.

How long does AS9100 certification take once I’ve selected a registrar?

If your QMS is already substantially implemented, expect roughly 3–6 months from signing with a registrar to certificate issuance, depending on internal readiness and registrar scheduling availability. This is the certification phase only — it doesn’t include building a QMS from scratch. See AS9100 Implementation Timeline for full phase-by-phase ranges depending on your starting point.

What happens if my registrar’s AS9100 accreditation scope doesn’t cover my activities or products?

Your certificate may not satisfy customer supplier-qualification requirements even if the audit itself goes well. Confirm that the certification body’s accredited scope covers the activities and products included in your proposed certification scope before signing, not after certification.


📥 Free Resources

AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification

ISO 13485 Gap Assessment Checklist — free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements

ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system

Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments

Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts


Not Sure What to Do Next?

🔹 You’re still researching registrar optionsWhat Is AS9100?AS9100 vs ISO 9001Aerospace Supplier Compliance Standards

🔹 You’re ready to request registrar quotes → Run your gap assessment first → AS9100 Rev D Gap Assessment Checklist

🔹 You need your team trained before Stage 1BSI Group AS9100 Training

🔹 You still need to buy the official AS9100 Rev D standardAS9100 / SAE Standards — ANSI Webstore

🔹 You want to understand certification costs and timeline firstHow Much Does AS9100 Certification Cost?AS9100 Implementation Timeline


The Registrar You Choose Is Part of Your Quality System

Certification is not a one-time transaction — it’s a multi-year relationship with surveillance audits every year and recertification every three. Choosing an accredited body with genuine aerospace auditor experience, transparent scope, and consistent auditor assignment saves far more over that relationship than a lower first-year quote.

At The Standards Navigator, complex standards are translated into practical, real-world guidance you can act on.

Aerospace suppliers don’t fail audits because the requirements are a mystery — they fail because they picked a registrar that didn’t understand their industry, or walked into Stage 1 without a real gap assessment behind them.

Organizations that treat registrar selection as a checkbox end up re-explaining their operation to a new auditor every surveillance cycle. Organizations that vet accreditation scope and auditor experience up front build a certification relationship that gets faster and smoother every year.

At The Standards Navigator, aerospace compliance gets the same clause-level treatment as everything else on this site — no fluff, no generic advice.

👉 Get updates on AS9100 certification, audits, and aerospace supply chain compliance
👉 Be first to access new gap assessment tools and aerospace-specific guides

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO 45001 vs ISO 50001: Which Safety and Energy Management Standard Does Your Operation Actually Need? (2026 Guide)

This guide compares ISO 45001 and ISO 50001 for manufacturers weighing safety versus energy management certification. It breaks down clause structure, standard pricing, certification triggers, and the most common mistakes teams make pursuing either standard. It also covers when facilities genuinely need both certifications versus when sequencing one after the other makes more sense.

How manufacturers decide between occupational safety and energy management certification

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Two Certifications, Two Very Different Problems

A plant manager doesn’t usually confuse safety and energy management. But when both show up on the same certification roadmap — often because a customer, insurer, or corporate sustainability mandate is pushing for both — the ISO 45001 vs ISO 50001 decision starts to feel more complicated than it actually is.

They don’t overlap much at all.

ISO 45001 exists to keep people from getting hurt. ISO 50001 exists to make sure your facility isn’t wasting energy it’s paying for. Both are voluntary management system standards. Both follow the same high-level structure. Both can be certified by an accredited registrar, resulting in a certificate you can put on a wall or a bid package. Past that, they’re solving two separate problems with two separate data sets, two separate risk registers, and — in most facilities — two separate teams.

From the Floor: I’ve sat in enough capital planning meetings to know that energy costs get treated as a fixed line item until someone forces the conversation — usually a spike in the utility bill or a customer asking about carbon reporting. In a fabrication environment, the big draws are exactly what you’d expect: compressed air systems, welding equipment, and cure ovens for coatings work. None of that gets measured systematically unless something formal requires it. That’s the gap ISO 50001 is built to close — not safety incidents, but the slow bleed of energy nobody’s tracking.

If you’re deciding whether your operation needs one of these standards, both, or neither yet, the fastest way through this decision is a structured gap check — not guesswork.

👉 Get the Manufacturing Compliance Checklist — Before you commit budget to either certification, run your operation against the core ISO, OSHA, and quality requirements that apply to production environments. Most teams find gaps in under 45 minutes.


In This Guide

  • What ISO 45001 and ISO 50001 actually cover
  • Quick answer: which standard fits which situation
  • Certification requirements, clause structure, and cost side by side
  • Who typically needs both
  • Common mistakes when pursuing either standard
  • Where to buy the standards and get training


👉 Start Here: Top Resources


Quick Answer: ISO 45001 vs ISO 50001

QuestionISO 45001ISO 50001
What it managesWorker health and safety riskEnergy performance and consumption
Core outcomeFewer injuries and incidentsImproved energy performance
Who typically drives itEHS / safety managerFacilities / energy manager, sometimes operations
Typical triggerCustomer requirement, insurance, incident historyUtility cost pressure, sustainability reporting, energy regulation
Legally mandatory?No — voluntary, though some contracts require itNo — voluntary, though some supply chains require it

If your driving concern is incidents, near-misses, or a customer asking about your safety program, that’s ISO 45001. If your driving concern is a utility bill that keeps climbing or a customer sustainability questionnaire, that’s ISO 50001. Many facilities don’t need to pursue both in the same certification cycle unless a specific contract or corporate mandate is forcing it.


What ISO 45001 Actually Requires

ISO 45001:2018 is the international standard for occupational health and safety (OH&S) management systems. It replaced OHSAS 18001 and is built on the same Annex SL high-level structure used across ISO 9001 and ISO 14001, which is one reason facilities already certified to those standards tend to find ISO 45001 implementation faster. ISO maintains the official scope and summary of the standard at iso.org, though that summary doesn’t substitute for the full requirements text you’ll need for actual implementation.

The standard requires organizations to identify hazards, assess OH&S risk, set objectives for reducing that risk, and demonstrate continual improvement — all under the same Plan-Do-Check-Act cycle used across the ISO management system family. It puts specific weight on worker participation and consultation, which is a heavier emphasis than most legacy safety programs are built around. OSHA’s own recordkeeping and general duty clause requirements, published at osha.gov, remain the regulatory floor in the U.S. regardless of whether a facility pursues ISO 45001 certification — the standard sits on top of that floor, not in place of it.

Most common finding: Facilities that already run a documented OSHA program tend to underestimate how much additional documentation ISO 45001 requires around worker consultation and leadership accountability — those clauses go beyond what OSHA compliance alone typically covers.


What ISO 50001 Actually Requires

ISO 45001 vs ISO 50001 article graphic showing an ISO 50001 energy performance dashboard, EnPI tracking, energy baseline, and continual improvement
ISO 45001 vs ISO 50001: ISO 50001 focuses on measuring and improving energy performance through energy baselines, EnPIs, targets, and continual improvement.

ISO 50001:2018 received the 2024 climate-action amendments, which added climate-change considerations to the management system’s context and interested-party requirements. That’s an amendment to the existing 2018 edition, not a new edition of the standard. The core structure hasn’t changed: establish an energy baseline, set energy performance indicators (EnPIs), and demonstrate measurable, continual improvement in energy performance — not just improvement in your management processes, but in your actual energy numbers.

From the Floor: In heavy fabrication, energy conversations rarely start with “let’s implement an energy management system.” They start with a compressor that runs unloaded all weekend, a cure oven that sits at temperature between jobs, or a welding bay where nobody has ever assigned energy consumption to the process. ISO 50001 gives operations a framework for turning those observations into measurable energy performance decisions instead of hallway complaints about the utility bill.

That’s the detail that trips people up. ISO 45001 doesn’t require you to hit a specific injury rate — it requires you to manage the system that reduces risk. ISO 50001 is more demanding on demonstrated energy performance: the standard requires organizations to establish, implement, maintain, and continually improve the EnMS while demonstrating improvement in energy performance. You can’t satisfy the standard with paperwork alone if your energy use isn’t actually trending in the right direction. The U.S. Department of Energy publishes separate technical guidance at energy.gov for organizations building out energy baselines and performance indicators, which can be a useful supplement alongside the standard itself.

An energy performance indicator (EnPI) is simply the metric you use to prove the trend is real — something like kWh per production unit, kWh per ton of material processed, energy consumption per operating hour, or energy consumption per batch. Pick a metric tied to actual output rather than relying solely on total facility consumption, because seasonal swings and production-volume changes can distort the picture.

👉 Setting up your first EnPI baseline without guidance is where most ISO 50001 implementations stall out. ISO 50001 Training from BSI and ISO 50001 Training from ISOQAR both cover EnPI methodology from the ground up, not just the paperwork.

If you are already tracking utility costs by building or by process line → you have the foundation ISO 50001 auditors expect to see; if you’re not, that’s the first gap to close before pursuing certification.


Clause Structure and Certification Cost Comparison

CategoryISO 45001:2018ISO 50001:2018
Structure10 clauses, Annex SL high-level structure10 clauses, Annex SL high-level structure
Core requirementManage OH&S risk, reduce injury/illnessEstablish EnPIs, demonstrate energy performance improvement
Standard PDF price$321.00 list / $256.80 ANSI member$293.00 list / $234.40 ANSI member
Typical driverCustomer/insurance requirement, incident historyUtility cost, sustainability reporting, energy regulation
Owning departmentEHS / SafetyFacilities / Energy / sometimes Operations

ANSI Webstore prices checked August 2026; prices may change — confirm current pricing before budgeting.

Standard purchase price is one line item — implementation and audit costs are the larger investment for either standard. For a full breakdown of ISO 45001 certification, audit, and implementation costs, see our ISO 45001 cost guide. Before selecting a registrar for either standard, verify their scope of accreditation through ANAB (anab.ansi.org) or IAF (iaf.nu) — not every accredited certification body carries scope for both OH&S and energy management audits.

If you’re evaluating both standards for your facility, check whether the ANSI bundle option covers both — compare the bundle price against purchasing each standard separately before you check out.


Do You Need Both?

Manufacturers typically don’t pursue ISO 45001 and ISO 50001 in the same cycle unless one of three things is happening:

  1. A major customer’s supplier scorecard requires both safety and energy management certification.
  2. Corporate ESG or sustainability reporting is pulling energy data into the same governance structure as safety data.
  3. The facility already holds ISO 9001 and/or ISO 14001 and is expanding its integrated management system to cover the full Annex SL family.

⚠️ If none of those apply to you right now, chasing both standards in the same year usually means neither implementation gets the attention it needs. Sequence them.

If you are already ISO 14001 certified → energy data collection is likely partially in place already, since environmental management systems frequently track energy as an aspect. That overlap is worth exploring before you start ISO 50001 from zero. We cover that specific comparison in ISO 14001 vs ISO 50001.

ISO 45001 vs ISO 50001 decision matrix comparing occupational health and safety management with energy management
ISO 45001 vs ISO 50001: Compare safety management, energy performance, key data, and implementation priorities for manufacturing operations.

Common Mistakes When Pursuing Either Standard

  • Treating ISO 50001 like a documentation exercise. Auditors want to see actual energy performance data trending in the right direction, not just a policy binder.
  • Underestimating worker participation requirements in ISO 45001. Facilities transitioning from legacy safety programs can discover gaps here during certification audits, particularly when participation is documented weakly.
  • Assuming one certification body handles both equally well. Confirm registrar experience with the specific standard before signing a contract — not every registrar has deep bench strength in energy management audits.
  • Skipping a baseline before setting objectives. For ISO 50001 specifically, you cannot demonstrate “improvement” without a documented starting point.

For a deeper look at where operations typically go wrong on the safety side specifically, see Common Mistakes in ISO 45001 Implementation.

Most operations managers don’t fail these audits because they misunderstand the standard. They fail because they assumed existing programs already covered the gap. Run a structured check before you commit to either certification path →

👉 Download the Manufacturing Compliance Checklist — see where your current safety and operational documentation actually stands against ISO requirements before you scope a project.


Readiness Checklist

✅ You track incidents, near-misses, or OH&S metrics in a documented format ✅ You know your facility’s baseline energy consumption by process or building ✅ Leadership has assigned clear ownership for whichever standard you’re pursuing
✅ You’ve confirmed whether a customer or contract actually requires certification, or just alignment
✅ You’ve budgeted for both the standard purchase and the registrar audit — not just one


Objection: “We Don’t Have the Budget or Headcount for Both”

This is the most common objection, and it’s usually a sequencing problem, not a resourcing problem. Most operations don’t need ISO 45001 and ISO 50001 running in parallel. Pick the one tied to your most immediate business driver — a customer requirement, an insurance conversation, or a utility cost that’s become impossible to ignore — and sequence the other for a later cycle. Trying to run both from zero at once is where budgets and internal bandwidth actually break down.

ISO 45001 vs ISO 50001 Stage 2 audit comparison showing occupational safety and energy management audit evidence
ISO 45001 vs ISO 50001: A Stage 2 audit examines different evidence for occupational health and safety management and energy management systems.

FAQ

Is ISO 45001 or ISO 50001 required by law?

Neither is legally mandatory in the U.S. Some customer contracts, insurance requirements, or international supply chain agreements may require one or both as a condition of doing business, but neither is a government regulation on its own.

Can one person manage both certifications?

In smaller operations, yes — but the skill sets are different. OH&S risk assessment and energy performance indicator tracking draw on different technical backgrounds, so expect a learning curve if one person is covering both.

How long does ISO 50001 certification take compared to ISO 45001?

Timelines are similar in structure — gap assessment, implementation, internal audit, Stage 1, Stage 2 — but ISO 50001 timelines depend heavily on how much energy metering infrastructure already exists. Facilities without submetering in place typically need additional time to establish a reliable baseline.

Does ISO 14001 certification make ISO 50001 easier?

Often, yes. Environmental management systems frequently already track energy as a significant aspect, which can shorten the baseline-gathering phase for ISO 50001. It’s not automatic, but the data collection habits usually transfer.

Is ISO 50001 only relevant for large facilities?

No. ISO 50001 applies regardless of facility size. Smaller operations sometimes see a faster payback because energy waste is easier to identify and correct when the operation is less complex.

What’s the single biggest difference between the two standards in a Stage 2 audit?

ISO 45001 audits focus heavily on documented risk assessments, worker consultation records, and incident investigation processes. ISO 50001 audits focus on your energy data — EnPIs, baseline documentation, and measurable performance trends. Auditors for the two standards are looking at fundamentally different evidence.

Do we need new equipment to pursue ISO 50001?

Not necessarily. Some facilities need submetering to establish a credible baseline, but many can start with existing utility billing data and building-level metering before investing in more granular monitoring.

Which standard should a fabrication shop pursue first?

For most fabrication and welding operations, safety risk (ISO 45001) is the more immediate driver — customer scorecards and insurance conversations tend to prioritize it. Energy management (ISO 50001) becomes the priority once utility costs or sustainability reporting requirements start showing up in bid packages.


📥 Free Resources

  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments.
  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system.
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts.

Not Sure What to Do Next?

🔹 Still researching which standard fits your operation? Start with the ISO 45001 Certification Guide or explore ISO Training for AS9100, ISO 13485 & ISO 50001 to understand what implementation actually looks like before committing.

🔹 Ready to start implementation? Get the Manufacturing Compliance Checklist and run a structured gap assessment before you scope a project with a consultant or registrar.

🔹 Need to buy the standard? If you’ve already decided which management system fits your operation, purchase ISO 45001:2018 or ISO 50001:2018 directly from ANSI Webstore — use code CC2026 for 5% off through December 31, 2026. If you’re implementing both, check the available bundle option before purchasing separately.

🔹 Getting your team certified to audit or lead either system? BSI and ISOQAR both run internal auditor and implementation courses for ISO 45001 and ISO 50001 — worth comparing before you pick one.

Whichever standard fits your situation, the fastest path forward isn’t guessing — it’s a structured comparison against your actual operation. The Standards Navigator covers both sides of this decision in plain, practitioner-level terms, without the sales pitch a registrar or consultant will give you.


Stop Guessing Which Standard Your Operation Needs

Facilities that wait for an audit finding or a customer scorecard to force the decision end up scrambling — picking whichever standard is most urgent instead of the one that actually fits their risk profile. Facilities that get ahead of it treat the decision as a planning exercise, not a fire drill.

The Standards Navigator breaks down ISO 45001, ISO 50001, and every standard in between in terms manufacturers can actually use on the shop floor — not the abstract language most registrars lead with.

👉 Get updates on ISO 45001, ISO 50001, and the full safety and energy management cluster
👉 Be first to access new gap assessment checklists and implementation resources as they publish

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO 45001 vs OSHA: What’s the Difference and Do You Need Both in 2026?

OSHA and ISO 45001 aren’t competing programs — one is a legal requirement, the other a voluntary management system standard. This guide breaks down the key differences, explains why ISO 45001 certification doesn’t replace OSHA compliance, and covers why manufacturers pursue both.

Understanding how the voluntary safety standard relates to your legal safety obligations

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Confusion That Costs Manufacturers Time

“We’re OSHA compliant — why would we need ISO 45001?”

I hear a version of that question every time this topic comes up, and it’s the wrong question. ISO 45001 vs OSHA isn’t a matchup between two competing programs. One is a legal floor you cannot opt out of. The other is a management system you choose to build on top of it. Confusing the two leads to two bad outcomes: companies that think a clean OSHA record means their safety program is sufficient, and companies that think ISO 45001 certification means they can stop worrying about 29 CFR.

Neither assumption holds up under an audit — or an inspection.

If you’re still deciding whether ISO 45001 is worth pursuing on top of your existing OSHA program, this is your evaluation-stage answer: what each one actually requires, where they overlap, and where they don’t.

I’ve sat through both an OSHA inspection and an ISO 45001 surveillance audit at the same facility within the same 12-month stretch. The OSHA compliance officer walked the floor checking us against specific 1910 line items — machine guarding, lockout/tagout, PPE. The ISO 45001 auditor wanted to see how we identified hazards and controlled risk before an incident happened, not just whether we were in violation on the day they showed up. Passing the OSHA inspection told us we weren’t currently non-compliant. Passing the ISO 45001 audit gave us evidence that our hazard-identification and risk-control process was actually being followed — not just that we’d avoided a violation that day. Those are two different questions, and manufacturers who only answer one of them are exposed. That perspective comes from 25+ years in heavy industrial operations and my work as a certified ISO 9001 Internal Auditor, where I’ve seen firsthand how a paper-compliant program and a working one aren’t always the same thing.

ISO 45001 vs OSHA comparison showing an OSHA inspection and ISO 45001 audit at the same manufacturing facility
ISO 45001 vs OSHA: an OSHA inspection evaluates compliance with workplace safety requirements, while an ISO 45001 audit evaluates the effectiveness of the occupational health and safety management system.

👉 Before your next inspection or audit — whichever comes first — run the Manufacturing Compliance Checklist against your current OSHA and ISO 45001 gaps in under 45 minutes.


In This Guide:

  • What OSHA actually requires (and enforces)
  • What ISO 45001 actually requires (and certifies)
  • A direct side-by-side comparison
  • Whether ISO 45001 certification satisfies OSHA obligations
  • Why manufacturers pursue both
  • Certification costs and where to start


👉 Start Here (Top Resources)


What Is OSHA?

The Occupational Safety and Health Administration is a US federal agency, and its standards are law, not guidance. OSHA enforces two primary sets of regulations: 29 CFR 1910 for general industry and 29 CFR 1926 for construction. Where no specific standard applies, OSHA may address certain recognized serious hazards under the General Duty Clause of the OSH Act, when the statutory requirements for a citation are met.

Compliance isn’t optional and it isn’t certified. It’s inspected, cited, and fined. OSHA also uses injury and illness data in its Site-Specific Targeting program to help identify establishments for inspection — for establishments covered by OSHA’s recordkeeping requirements, that means accurate 300 log data is more than a paperwork exercise, since it can factor into the agency’s targeting process.


What Is ISO 45001?

ISO 45001 is the international standard for occupational health and safety management systems, published by the International Organization for Standardization. Unlike OSHA, it’s voluntary — no government requires it — and it’s built around a management system framework rather than a fixed list of technical requirements.

Where OSHA establishes specific requirements for things such as machine guarding, fall protection, or lockout/tagout, ISO 45001 tells you how to build a system that identifies hazards, sets objectives, assigns responsibility, and drives continual improvement — regardless of what those specific hazards turn out to be. It shares the same high-level structure as ISO 9001 and ISO 14001, which is why many manufacturers pursuing quality or environmental certification eventually add ISO 45001 to build an integrated management system.

Certification is third-party: an accredited certification body audits your system against the standard and issues (or withholds) certification. OSHA doesn’t do this — there’s no “OSHA-certified” facility, only inspected and cited or not.


ISO 45001 vs OSHA: Key Differences

CategoryOSHAISO 45001
Legal statusMandatory US federal lawVoluntary, internationally recognized
Geographic scopeUnited States onlyGlobal — any country, any operation
StructureFixed technical requirements (29 CFR 1910/1926)Management system framework (Plan-Do-Check-Act)
EnforcementInspections, citations, finesThird-party audits, certification/decertification
FocusCompliance with specific hazard rulesContinual improvement of the safety management system
DocumentationRequired records (300 logs, training records)Documented information tied to risk methodology and objectives
Proof of complianceRegulatory compliance and enforcement recordThird-party certification status
Who requires itFederal government, for covered employersCustomers, contracts, insurers, corporate policy

Most common finding: manufacturers who treat OSHA compliance as their ceiling instead of their floor tend to have reactive safety programs — reacting to the last incident instead of preventing the next one. ISO 45001’s risk-based clauses (6.1, 8.1) push you toward the second approach.


Does ISO 45001 Certification Satisfy OSHA Requirements?

No — and this is the objection worth addressing directly, because it’s the most common misunderstanding I run into. ISO 45001 certification is not a substitute for OSHA compliance, and no certification body, registrar, or consultant can tell you otherwise.

In fact, ISO 45001 requires the opposite relationship. Clause 9.1.2 (Evaluation of Compliance) obligates a certified organization to actually identify and evaluate compliance with its applicable legal requirements — which, for a US manufacturer, means OSHA. A properly built legal register under ISO 45001 should identify the OSHA requirements applicable to your operations, along with a method for evaluating ongoing compliance with them — the standard doesn’t prescribe a fixed format or require every applicable CFR citation listed by name, just a process that actually works. So instead of replacing OSHA, ISO 45001 formalizes your ongoing evaluation of it.

ISO 45001 vs OSHA process diagram showing how OSHA requirements connect to ISO 45001 risk assessment, operational controls, compliance evaluation, and continual improvement
ISO 45001 vs OSHA: OSHA establishes workplace safety requirements, while ISO 45001 provides a management system for identifying risks, implementing controls, evaluating compliance, and driving continual improvement.

If you are already OSHA compliant and considering ISO 45001 → think of it as building the management system layer that keeps you compliant consistently, not a separate safety program running in parallel.

👉 Already OSHA compliant? See what it takes to add ISO 45001 on top of your existing safety program in our ISO 45001 Certification Guide.


Why Manufacturers Pursue ISO 45001 on Top of OSHA Compliance

If OSHA is mandatory, why add a voluntary standard? A few recurring reasons show up across the shops and plants I’ve worked in and consulted with:

Customer and contract requirements. Tier 1 and Tier 2 suppliers increasingly see ISO 45001 certification listed as a bid requirement. OSHA compliance alone doesn’t satisfy that contract language — certification does.

Insurance and risk-management considerations. A documented, auditable safety management system can give insurers and other stakeholders additional evidence of how you manage OH&S risk, beyond incident-rate data alone.

Integrated management systems. If you’re already certified to ISO 9001 or ISO 14001, adding ISO 45001 is typically less work than starting from zero — the harmonized clause structure means document control, internal audits, and management review can largely be reused. See our guide on integrating ISO 9001, ISO 14001, and ISO 45001.

ISO 45001 vs OSHA comparison showing how both systems respond to an unguarded machine hazard in a manufacturing facility
ISO 45001 vs OSHA: OSHA focuses on compliance with applicable requirements, while ISO 45001 provides a systematic approach to identifying hazards, controlling risk, auditing performance, and driving continual improvement.

Reducing incident recurrence. OSHA’s enforcement model centers on evaluating conditions against existing standards — inspections, complaints, targeted programs. ISO 45001’s risk assessment clauses (6.1.2) add a layer on top of that: identifying and controlling hazards upstream, before they reach the point of a citation or an injury.

If you are under customer pressure to certify quickly → prioritize training and select your certification body before you start building documentation from scratch. Don’t reverse that order — it’s the single most common mistake we cover in our article on common mistakes in ISO 45001 implementation.

If you are not sure how long certification will realistically take alongside your existing OSHA program → our ISO 45001 implementation timeline breaks out the phases and typical duration.


OSHA Recordkeeping and ISO 45001: Where the Data Overlaps

⚠️ Verify current OSHA.gov requirements before treating this as final — OSHA’s electronic recordkeeping requirements have expanded over time, with certain covered establishments required to submit specified injury and illness records electronically. Because those requirements depend on factors like establishment size and industry classification, confirm which forms and deadlines apply to your operation directly with OSHA.gov. Whatever your submission requirement, that 300 log data is also a primary input for ISO 45001’s incident investigation (clause 10.2) and continual improvement (clause 10.3) processes — clean, accurate logs generally make nonconformity trend analysis far less painful, since the underlying data already exists in usable form.

Quick Audit-Readiness Checklist

✅ Legal register identifies your specific applicable OSHA standards (not a generic reference to “OSHA”)
✅ OSHA 300, 300A, and 301 logs are current, accurate, and reconciled against your incident investigation records
✅ Risk assessment methodology (6.1.2) references actual hazards observed on your floor — not a generic template
✅ Internal audit program covers both ISO 45001 clauses and applicable OSHA standards in scope
✅ Management review minutes show OSHA compliance status as a standing agenda item

⚠️ If your legal and other requirements register hasn’t been reviewed since your last major regulatory or operational change, update it before your surveillance audit


When You Need Both

You probably need both when:

  • OSHA applies to your US operation — which covers nearly every manufacturer reading this.
  • A customer, contract, corporate policy, or market requirement calls for ISO 45001 certification specifically.
  • You want a formal OH&S management system that integrates with an existing ISO 9001 or ISO 14001 certification.

You probably don’t need ISO 45001 solely because OSHA exists. OSHA compliance is the baseline every covered US employer already carries — ISO 45001 is worth the investment when one of the three drivers above actually applies to your operation.


Certification Cost and Where to Start

If you’re purchasing the standard itself, the current edition is available through the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026 via the ANSI coupon link. If you’re planning to pursue ISO 9001 or ISO 14001 alongside ISO 45001, buying the standards bundled together costs meaningfully less than purchasing each one separately.

For a full breakdown of certification, audit, and implementation costs, see How Much Does ISO 45001 Cost? OSHA compliance itself carries no certification fee — your cost there is entirely internal: training, engineering controls, PPE, and recordkeeping systems.


FAQ

Is ISO 45001 required by law?

No. ISO 45001 is a voluntary international standard. OSHA compliance, by contrast, is legally mandatory for covered US employers regardless of certification status.

If I’m ISO 45001 certified, can OSHA still cite me?

Yes. Certification has no bearing on OSHA’s authority to inspect and cite. The two operate independently — one enforced by a federal agency, one verified by a private accredited registrar.

Does ISO 45001 replace the need for an OSHA-compliant safety program?

No. ISO 45001 clause 9.1.2 specifically requires you to evaluate compliance with applicable legal requirements, including OSHA — so certification depends on maintaining OSHA compliance, not replacing it.

Can ISO 45001 certification be completed in 6 months?

Rarely, for a facility starting from an informal safety program. Manufacturers with an OSHA-compliant baseline and dedicated resources may be able to reach certification in roughly 8–12 months. See our implementation timeline for the phase-by-phase breakdown.

Which OSHA standard aligns most closely with ISO 45001?

There isn’t a direct regulatory counterpart — OSHA’s 1910 and 1926 are technical, hazard-specific regulations, while ISO 45001 is a management-system framework. The two aren’t equivalents. Instead, ISO 45001’s risk-based framework gives you a systematic way to manage the same hazards OSHA regulates piecemeal through dozens of individual standards.

Is ISO 45001 worth it if we already have a strong OSHA safety record?

A clean OSHA record shows you haven’t been cited — it doesn’t verify that your hazard identification process would catch the next risk before it becomes an incident. For manufacturers under contract pressure to certify, ISO 45001 adds a layer OSHA compliance alone doesn’t provide.

Do OSHA regulations apply outside the United States?

No. OSHA requirements generally apply within the United States and its territories, while ISO 45001 can be applied by organizations worldwide, which is one reason multinational manufacturers often standardize on it.

What happens during an ISO 45001 audit versus an OSHA inspection?

An OSHA inspection checks current conditions against specific regulatory line items and can result in citations. An ISO 45001 audit evaluates whether your management system is functioning as designed and can result in nonconformities that must be closed to keep certification.


📥 Free Resources

  • ISO 9001 Roadmap — step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts

Not Sure What to Do Next?

🔹 Still researching whether ISO 45001 fits your operation? Start with our ISO 45001 Certification Guide for the full picture before committing resources.

🔹 Ready to start building your system? Run the Manufacturing Compliance Checklist against your current OSHA and ISO 45001 gaps, and review our ISO 45001 Documentation Requirements guide before you start drafting.

🔹 Need to purchase the standard or line up training? Get the current edition from the ANSI Webstore (code CC2026 for 5% off), then compare BSI and ISOQAR training options.

OSHA compliance keeps you legal. ISO 45001 keeps your safety program honest about whether it actually works. The Standards Navigator covers both sides of that equation so you’re not caught treating one as a substitute for the other.


Before You Go

Most manufacturers don’t get into trouble because they misunderstand OSHA — they get into trouble because they assume their OSHA compliance history means their broader safety system has no gaps. Facilities that struggle tend to treat their 300 log as a filing obligation. Facilities that succeed treat it as an input into a system that’s actively looking for the next problem.

The Standards Navigator covers both the regulatory floor and the certification layer manufacturers build on top of it — OSHA, ISO 45001, and everywhere they intersect.

👉 Get updates on ISO 45001 implementation, audits, and OSHA alignment
👉 Be first to access new safety and compliance checklists as we publish them

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

ISO 45001 Documentation Requirements: What Manufacturers Need for 2026

ISO 45001 requires documented information throughout the standard, organized here into practical maintain-and-retain categories. This guide breaks down what auditors most commonly request, clause by clause, and covers the documentation gaps that create findings before manufacturers know to look for them.

The Mandatory Records, Policies, and Procedures Your OH&S Management System Must Have

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


You Don’t Fail an ISO 45001 Audit Because of Your Safety Program. You Fail It Because You Can’t Prove It.

Most manufacturers with a real safety culture assume that’s enough. It isn’t. Auditors evaluate your ISO 45001 documentation requirements just as closely as your actual safety performance, and a strong program with weak documentation behind it still produces findings.

An auditor doesn’t walk your floor and take your word for it. They ask for documented information — the specific policies, records, and evidence ISO 45001 requires you to maintain and retain. If the required documented information isn’t available, controlled, or retrievable when the auditor needs objective evidence, you’re creating a potential nonconformity. It doesn’t matter how few incidents you’ve had.

This is where documentation-ready operations separate from everyone else. Not because their safety performance is better on paper, but because their paper actually matches what happens on the floor. The goal isn’t a five-minute retrieval requirement from ISO — that’s not written anywhere in the standard. It’s an operational test: if someone asks for evidence, can your team find the right record quickly, without reconstructing history on the spot?

From the Floor: I’ve sat across the table from an auditor who asked for evidence that a hazard identification process had actually been followed on a specific line — not the procedure, the record that it happened. We had the procedure. We didn’t have three months of the records behind it, because the paperwork existed as a form nobody was consistently filling out. That gap turned a strong safety program into a documented nonconformity, and it took us most of a quarter to close the loop on retraining and evidence.

If you’re not sure your OH&S management system would survive that same request, run the Manufacturing Compliance Checklist against your current files before your next audit — it takes less than an hour and tells you exactly where the gaps are. If you haven’t mapped out your certification timeline yet, our ISO 45001 Implementation Timeline breaks down when documentation work should start relative to your target audit date.


In This Guide

  • What “documented information” means under ISO 45001 and why the term matters
  • The specific documents you’re required to maintain (policies, procedures, plans)
  • The specific records you’re required to retain (evidence of what actually happened)
  • A quick-reference maintain vs. retain matrix you can hand to your team
  • Where manufacturers commonly fall short — and the finding it produces
  • Whether you need a full OH&S manual (you don’t)
  • What to do about the ISO 45001 revision while you finalize documentation

Quick Answer: ISO 45001 Documentation at a Glance

CategoryWhat ISO 45001 RequiresClause
Scope statementDocumented boundaries and applicability of the OH&S system4.3
OH&S PolicyDocumented, communicated, and available policy statement5.2
Roles & responsibilitiesDocumented assignment of OH&S roles, responsibilities, authorities5.3
Risks, opportunities & related actionsDocumented information on OH&S risks, opportunities, and the processes/actions needed to address them6.1.1
OH&S risk assessment methodology & criteriaMethodology and criteria for assessing OH&S risks, maintained and retained6.1.2.2
Objectives & plansOH&S objectives and plans to achieve them — maintained and retained6.2.1–6.2.2
Worker consultation & participationDocumented, maintained process for consultation and participation (records recommended as evidence)5.4
Competence evidenceRecords proving workers are competent for their OH&S-related duties7.2
Operational controlsDocumented information maintained and retained to the extent needed to show processes were carried out as planned8.1.1
Emergency preparednessDocumented process for preparing for and responding to potential emergencies8.2
Emergency response testingEvidence that emergency response processes are periodically tested and evaluated8.2
Legal & other requirementsApplicable OH&S legal and other requirements identified and kept current6.1.3
Compliance evaluationResults showing applicable requirements were periodically evaluated9.1.2
Internal audit & management reviewAudit program, audit results, and management review records9.2, 9.3
Incidents & corrective actionRecords of nonconformities, incidents, and actions taken10.2

(This is the practical short list. The detailed breakdown of the core requirements follows below.)

👉 Start Here (Top Resources)


What “Documented Information” Actually Means

ISO 45001 doesn’t use the words “documents” and “records” the way most operations managers use them. It uses one term — documented information — and requires it throughout nearly every clause in the standard, from the scope statement in Clause 4.3 through corrective action in Clause 10.2. The standard groups that documented information into two functions rather than two separate document types.

Maintained documented information generally supports keeping information current as part of the management system. Your OH&S policy, your scope statement, your risk assessment methodology — these are maintained, meaning they’re kept up to date as your operation changes.

Retained documented information provides evidence that an activity, process, or result actually occurred. Your training records, your incident reports, your internal audit results — these are retained as proof something happened, not as a living reference document.

The distinction matters because auditors ask for both, and they’re looking for different things. A maintained document shows your system is designed correctly. A retained record shows your system is actually being followed. A gap between the two — a well-designed procedure with no consistent evidence behind it — is exactly what happened in the anecdote above.

The tables below organize the core ISO 45001 documentation requirements into practical categories for implementation. ISO 45001 doesn’t present these as a fixed numbered checklist — the requirement is distributed across the clauses — but the items below represent the core documentation auditors most commonly request during certification audits.

One of the more common documentation gaps: a documented procedure exists, but there’s no retained evidence that it’s been executed consistently over time. The procedure isn’t the problem. The missing paper trail behind it is.

Not sure your current documentation would hold up? Before you invest in a documentation overhaul, run the Manufacturing Compliance Checklist — most operations managers find the gap is narrower, and more fixable, than they expected.


The Documents You’re Required to Maintain

These are the “maintained” items — the documents ISO 45001 requires you to keep current and available, mapped to the clause that requires them.

DocumentClauseWhat It Must Cover
Scope of the OH&S management system4.3Boundaries, applicability, sites and activities covered
OH&S Policy5.2Commitment to safe conditions, hazard elimination, legal compliance, worker consultation
Roles, responsibilities, and authorities5.3Who owns which OH&S function, documented and communicated
Risks, opportunities, and related actions6.1.1OH&S risks, opportunities, and the processes/actions needed to address them
OH&S risk assessment methodology and criteria6.1.2.2The methodology and criteria used to assess OH&S risk — maintained and retained as documented information
OH&S objectives and plans to achieve them6.2.1, 6.2.2Measurable objectives tied to the policy, with a plan, resources, and timeline — maintained and retained as documented information
Operational planning and control criteria8.1.1The criteria established for processes needed to meet OH&S requirements — also both maintained and retained
Emergency preparedness and response process8.2How the organization identifies and prepares to respond to potential emergency situations

If you are building this system from scratch, this table is your starting checklist. Each category corresponds to documented-information requirements in ISO 45001:2018, though the exact number and format of documents you create will depend on your organization’s size, complexity, risks, and processes.

If you plan to certify through a specific registrar, ANAB and IAF both maintain public accreditation records you can check before selecting a certification body — it’s a quick way to confirm a registrar’s accreditation is current before you invest documentation time around their specific audit expectations.

If you are already ISO 9001 or ISO 14001 certified → most of this structure already exists in your management system. ISO 45001 shares the same high-level structure, so your scope statement, policy format, and objectives-planning process can largely be adapted rather than built new. Our Integrated Management Systems guide walks through exactly how to combine them.

ISO 45001 documentation requirements showing how procedures, workplace activities, and retained records become audit evidence
ISO 45001 documentation requirements connect written procedures, actual workplace activities, and retained records to create objective audit evidence.

The Records You’re Required to Retain

These are the “retained” items — the evidence that proves your system actually operated the way the maintained documents say it should.

RecordClauseWhat It Proves
Legal and other requirements register6.1.3Applicable OH&S legal and other requirements have been identified and kept current
Compliance evaluation results9.1.2The organization periodically evaluated whether those requirements are actually being met
Risk assessment methodology and criteria6.1.2.2The methodology and criteria used to assess OH&S risk are maintained and retained as documented information
OH&S objectives and plans to achieve them6.2.2The organization’s OH&S objectives and plans are maintained and retained as documented information
Worker consultation and participation records (recommended)5.4, 7.4.1Clause 5.4 requires a maintained process for consultation and participation; it doesn’t itself mandate a specific retained record. Retaining evidence — meeting notes, consultation logs — is standard practice and often overlaps with the communication records already required under 7.4.1
Evidence of competence7.2Workers performing OH&S-related tasks are qualified for them
Communication records7.4.1Internal and external OH&S communications actually occurred
Operational control evidence8.1.1Documented and retained to the extent necessary to have confidence that processes were carried out as planned
Emergency response testing8.2Evidence that the planned emergency response capability was periodically tested and evaluated
Monitoring, measurement, and calibration9.1.1Performance data is accurate and equipment is verified
Internal audit program and results9.2.2The management system is being checked against itself, on a planned interval
Management review records9.3Leadership is actually reviewing OH&S performance, not delegating it entirely
Nonconformity and corrective action records10.2Evidence that nonconformities and incidents were addressed, corrective actions were taken, and their effectiveness was evaluated
Continual improvement evidence10.3Evidence that the OH&S management system is continually improved

If you’re three to six months from your planned Stage 1 audit → this is a useful table to work backward from. An auditor sampling your system will ask for evidence across these categories, and gaps here tend to be more damaging than gaps in the maintained documents above, because a missing record can’t be written retroactively without it looking exactly like what it is.

Quick-Reference: Maintain vs. Retain by Requirement Area

Requirement AreaMaintainRetain
Scope
OH&S Policy
Risk & Opportunity Methodology
Objectives
Legal & Other Requirements
Worker Consultation & Participation
Competence
Emergency Preparedness
Operational Controls
Internal Audit
Management Review
Corrective Action

Note: This matrix is a practical implementation guide, not a substitute for reviewing the specific documented-information requirements in each clause. Whether you maintain or retain information, and in what form, depends on the applicable requirement and your organization’s processes. One nuance worth flagging: Worker Consultation & Participation is checked under Maintain because Clause 5.4 requires a maintained process — the clause itself doesn’t mandate a specific retained record, though retaining evidence of consultation is standard practice and strongly recommended.

According to ISO.org, ISO 45001 was developed to give organizations a framework for managing occupational health and safety risk in a way that’s auditable and comparable across industries, not just a policy statement of intent — which is why the standard leans so heavily on retained evidence rather than stated commitment.

ISO 45001 documentation requirements explained through maintained documents and retained records for an audit-ready OH&S management system
ISO 45001 documentation requirements distinguish between information organizations maintain to guide their OH&S system and records they retain as evidence that it operates as intended.

Do You Need a Formal OH&S Manual?

No. This is a common misconception carried over from older safety standards. ISO 45001 does not require a standalone OH&S manual as a mandatory document. The standard cares about whether the required documented information exists and is controlled — not whether it’s bound into a single manual.

That said, many organizations still choose to build one, because it’s a practical way to organize the required documents and make them easy to locate during an audit. If your team already thinks in terms of a manual from ISO 9001 or ISO 14001 work, keeping the format is often faster than fighting it. The manual itself just isn’t the requirement — the underlying documented information is.


Common Documentation Mistakes That Trigger Findings

Writing procedures nobody follows. A documented process that doesn’t match actual floor practice is worse than no document at all — it hands the auditor a direct comparison between what you say you do and what you actually do.

Treating documentation as a one-time project. Documented information under Clause 7.5.3 has to be controlled — reviewed, updated, and version-controlled over time. A policy written for certification and never touched again is a stale document waiting to be flagged.

No traceable link between the risk assessment and the objectives. Auditors increasingly check whether your OH&S objectives actually connect back to the hazards your risk assessment identified. If your objectives read like generic safety goals with no tie to your specific risk profile, that disconnect gets noticed.

Missing evidence of worker consultation. Clause 5.4 requires a maintained process for consulting and involving workers — it doesn’t itself spell out a specific retained record. In practice, though, auditors expect to see evidence that consultation actually happened: meeting notes, sign-off sheets, toolbox-talk logs. This is frequently missed in fast-moving fabrication and production environments, where consultation happens informally on the floor and never makes it into any retained record at all.

⚠️ If any of these sound familiar, address them before your audit window closes, not after a finding forces the issue. Most of them are a documentation fix, not an operational overhaul — but only if you catch them early enough to build the evidence trail.

If you’re running ISO 45001 alongside ISO 9001 or ISO 14001, our ISO 14001 Documentation Requirements guide covers the same maintain-versus-retain distinction from the environmental side, and the two documentation sets typically share more structure than teams expect.


Should You Wait for the ISO 45001 Revision Before Finalizing Your Documentation?

No. The revision of ISO 45001, expected to become the 2027 edition, is now at the Draft International Standard (DIS) stage, with the DIS ballot underway as of mid-2026. ISO 45001:2018 remains the current published, certifiable standard while that ballot runs. No final publication date is confirmed, and no transition timeline for existing 2018 certificate holders has been formally published.

Organizations pursuing certification today should continue building documentation to ISO 45001:2018. Even if the eventual revision introduces new requirements, a well-documented OH&S management system gets updated when a standard revises — it doesn’t get rebuilt from zero. Waiting on documentation you need for certification now, based on a revision that hasn’t reached final publication, puts your current certification timeline at risk for no protective benefit.

A team can understand ISO 45001 perfectly and still stumble at audit time because it assumed a document existed somewhere that nobody had actually built. Run the readiness checklist below before that assumption costs you an audit cycle →


ISO 45001 documentation requirements audit-readiness dashboard showing key evidence areas, records, and compliance status
ISO 45001 documentation requirements help organizations verify that key OH&S evidence is current, complete, retained, and ready for an audit.

ISO 45001 Documentation Readiness Checklist

✅ Scope statement is documented, dated, and matches your actual sites and activities
✅ OH&S policy is signed, communicated, and available to workers — not just filed
✅ Risk assessment methodology is documented and consistently applied, not ad hoc
✅ OH&S objectives trace back to specific identified risks
✅ Evidence of worker consultation and participation exists and is retained
✅ Legal and other requirements register is current, not built once and forgotten
✅ Internal audit program has actually run — not just been scheduled
✅ Management review meetings are documented, with dated minutes and action items
✅ Corrective action records show root cause analysis, not just “issue resolved”
Emergency response process has been tested, and the test is documented

If you checked fewer than eight of these, download the Manufacturing Compliance Checklist and work through the gaps before you schedule a certification audit — closing them after a finding costs far more time than closing them before one.


Frequently Asked Questions

Does ISO 45001 require a documented OH&S manual?

No. ISO 45001 requires specific documented information listed throughout the standard, but it does not mandate a single bound manual. Many organizations build one anyway for organizational convenience, but it is not a certification requirement.

Can I use my existing ISO 9001 or ISO 14001 documentation system for ISO 45001?

Largely, yes. ISO 45001 shares the same high-level structure as ISO 9001 and ISO 14001, which means your document control process, management review format, and internal audit program can typically be extended to cover OH&S rather than rebuilt separately. The content — your risk assessment methodology, your OH&S-specific objectives — still has to be built specifically for occupational health and safety.

How many documented procedures does ISO 45001 actually require by name?

ISO 45001 doesn’t specify a fixed number of documents by name. It requires documented information throughout multiple clauses — the tables above organize those requirements into the categories auditors most commonly request during certification. The exact number of individual procedures you write depends on your operation’s size and complexity — a 30-person fabrication shop and a 500-employee facility will document the same clauses very differently in scope and detail.

Is 3 months enough time to build ISO 45001 documentation from scratch?

For a small operation with an existing safety program to formalize, it’s tight but possible if documentation work starts immediately and runs in parallel with any remaining implementation gaps. For an organization building both the OH&S program and its documentation from zero, 3 months is an aggressive timeline that typically compresses the record-retention evidence auditors look for most closely.

What happens if I’m missing a required record during my audit?

If a requirement calls for retained documented information and the organization can’t provide the required evidence, the auditor may raise a nonconformity. The significance depends on the nature and extent of the gap and the certification body’s audit determination — missing evidence of an ongoing process, like consistent hazard identification records, tends to raise more concern than a single administrative gap, because it questions whether the process is actually operating.

Do digital record-keeping systems satisfy ISO 45001 documentation requirements?

Yes. ISO 45001 is explicit that documented information can exist in any format or medium, including electronic systems, as long as it’s controlled — meaning it’s identifiable, retrievable, protected from unauthorized changes, and available where it’s needed.

How long do I need to retain OH&S records?

ISO 45001 does not specify one universal retention period for every OH&S record. Retention periods can depend on applicable legal and other requirements, the organization’s own needs, and the type of documented information involved. Check applicable requirements directly through OSHA.gov and other relevant authorities rather than assuming a single retention period applies across all record types.

Does documentation quality affect certification cost?

Indirectly, yes. Weak documentation extends audit time, increases the likelihood of findings that require a follow-up audit, and can push out your certification timeline. Our ISO 45001 cost breakdown covers how audit findings translate into real cost.


📥 Free Resources

  • ISO 9001 Roadmap — a step-by-step implementation guide for manufacturers building or improving a quality management system, useful if you’re documenting an integrated system alongside ISO 45001.
  • Manufacturing Compliance Checklist — a practical compliance reference covering key ISO, OSHA, and quality documentation requirements for production environments.
  • Supplier Quality Checklist — an evaluation tool for assessing supplier quality controls and flow-down compliance, useful when your OH&S documentation extends to contractor and supplier requirements.

Not Sure What to Do Next?

🔹 Still researching what ISO 45001 actually requires? Start with our ISO 45001 Certification Guide for the full picture before you commit to a documentation project.

🔹 Ready to start building your documentation? Download the Manufacturing Compliance Checklist and map your current files against it before you write a single new procedure.

🔹 Need to buy the standard itself? Get ISO 45001:2018 from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026, and ANSI Webstore serves international buyers in multiple languages if you’re documenting across sites outside the US.

🔹 Want structured help closing documentation gaps? Compare ISO 45001 training through BSI Group against ISOQAR’s ISO 45001 course to see which fits your team’s timeline and budget.

Documentation is where most ISO 45001 certification timelines quietly slip. The Standards Navigator exists to make sure yours doesn’t — clear breakdowns of exactly what the standard requires, without the guesswork.


Struggling to Keep Your OH&S Records Audit-Ready?

Some operations build a safety program first and scramble to document it later. Others build the documentation structure alongside the program from day one — and walk into their Stage 1 audit without a single scramble.

The Standards Navigator covers ISO 45001 documentation, implementation timelines, and certification costs specifically for manufacturers who need the practical answer, not the theoretical one.

👉 Get updates on ISO 45001 documentation and audit-readiness content
👉 Be first to access new OH&S checklists and gap-assessment tools

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.