Decedent Care: Why ISO 7101 Adoption Wins Family Trust

Direct Answer

Decedent care is everything a hospital does from the moment of death until the person leaves the building — pronouncement, family viewing, personal effects, donation referral, autopsy, morgue custody, identification, and release to a funeral home. Federal law regulates only the donation referral at the front of that chain. The rest sits in most hospitals without a process owner, without an audit objective, and without a single metric in management review. ISO 7101 adoption is the most direct route to closing it, because it is the only management system standard that makes dignity and people-centred care explicit requirements rather than values statements — and because the family, not the patient, is the service user for every step of decedent care that follows death.

Decedent care is the one clinical pathway that ends after the patient does, which is exactly why most quality management systems never follow it to the end. In January 2026, a Rhode Island hospital released a decedent to the wrong funeral home. A family held a service and buried a stranger. The error surfaced only when a second funeral home came looking for the person who had already been buried under someone else's name.

The hospital's public statement said something that should stop every quality professional reading it: that strict policies and procedures govern all morgue operations , and that additional safeguards would be implemented. Both things can be true at once. Policies existed. The control did not.

The funeral director who collected the remains described the verification problem more precisely than any procedure document has. She takes a photograph of the deceased, photographs the toe tag and the body bag, and reviews the morgue paperwork — and still, as she put it, there is no real way of knowing beyond trust in institutions, name tags, and paperwork. A person who has been ill and then in refrigeration does not necessarily resemble a photograph. So the entire identity control at the final handoff rests on a tag, a form, and the assumption that the person who attached the tag was correct.

Trust is not a control. It is a hiring outcome. And in decedent care it is doing work that in any other custody chain in the hospital — blood products, controlled substances, specimens, implants — would be done by two-person verification against an independent identifier.

This article is not an argument that hospitals are careless. It is an argument that decedent care has been left structurally unmanaged across the sector, that federal regulation covers only its first step, and that ISO 7101 adoption offers a genuine and currently unclaimed way to fix it. Almost no U.S. healthcare organization has implemented ISO 7101 yet, which makes this an opportunity rather than a deficiency.


Scope

What Decedent Care Actually Covers — and Where the QMS Stops

Pathway. Custody. Handoff.

Write out the decedent care pathway as a process map and its length surprises people who have worked next to it for years. Pronouncement and documentation of death. Notification of next of kin. Referral to the organ procurement organization. Family presence and viewing at the bedside. Removal of lines, tubes, and devices. Preparation and identification tagging. Collection and release of personal effects and valuables. Transport to the morgue. Refrigerated storage with a capacity limit and a clock. Autopsy consent, performance, and organ retention decisions. Death certificate completion and filing. Coroner or medical examiner referral where the death is reportable. Identification verification at release. Handoff to a funeral home, crematory, or anatomical donation program. Records retention and release of information to the estate.

Fifteen or more steps, crossing nursing, chaplaincy, pathology, security, health information management, patient relations, and environmental services, with three or four external providers attached at the end. Now ask the question a certification auditor would ask: who owns this process? In most hospitals, nobody does. The pathway is a series of departmental habits that meet at the morgue door, and the morgue door is usually where written procedure gets thinnest and staffing gets lightest.

The reason is structural rather than cultural. Quality management systems in healthcare are built around patient outcomes, and the patient's outcome is fixed. The measures stop. The registry closes. The care team disperses. What remains is an obligation to a different party — the family — that no clinical metric captures and no patient satisfaction instrument surveys. Decedent care is the pathway where the customer changes identity halfway through, and management systems that never named the second customer have no mechanism to serve them.

Contrast that with how the same hospital treats a comparable custody chain. A unit of blood carries a unique identifier, a two-person bedside verification, a documented chain of custody, a temperature log, a wastage record, and a reconciliation the transfusion service performs on a schedule. A controlled substance carries a count at every shift change, witnessed waste, and a discrepancy investigation triggered automatically. Both are audited. Both appear in committee minutes. A human being in decedent care frequently carries a tag and a form.


Regulation

What CMS Already Requires in Decedent Care — and Where It Ends

Referral. Training. Silence.

Direct Answer

Federal law reaches exactly one step of decedent care. The Medicare Condition of Participation at 42 CFR 482.45 requires every hospital to hold a written agreement with its organ procurement organization and to notify that OPO in a timely manner of every death and every imminent death. HIPAA then protects the decedent's health information for fifty years after death. Between those two bookends — custody, identification, effects, autopsy, and release — there is no federal standard, no inspection, and no reporting requirement.

The front of the pathway is genuinely well regulated, and it is worth being precise about what that regulation does. 42 CFR 482.45 requires a hospital to have and implement written protocols incorporating an agreement with an OPO under which it notifies the OPO, in a timely manner, of individuals whose death is imminent or who have died in the hospital. It requires agreements with at least one tissue bank and one eye bank. It requires that families of potential donors be informed of the option to donate, that the request be made by a trained designated requestor, and that staff who work with OPO, tissue bank, and eye bank personnel receive training on donation issues. Critical access hospitals carry the same duties at 42 CFR 485.643.

CMS surveyor guidance is emphatic that notification applies to every death, not to deaths a clinician judges promising, and that when death is imminent the notification has to happen before withdrawal of ventilation while organs remain viable. Hospitals also work cooperatively with the OPO on death record review to improve identification of potential donors. CMS guidance on OPO agreements confirms that every participating hospital must hold one.

That is real regulatory architecture, and hospitals generally comply with it well, because it is surveyed. Note what it covers: a referral decision and a conversation with a family, both occurring in the first hours. It says nothing about how the person is identified in the morgue eleven hours later, who verifies that identity at release, whether effects were reconciled, or whether the crematory ever confirmed receipt.

At the far end of decedent care, one other federal requirement quietly persists. The HIPAA Privacy Rule protects a decedent's individually identifiable health information for fifty years following the date of death, with disclosure permitted to a personal representative, and by specific exception to coroners, medical examiners, funeral directors, and organ procurement organizations. Most hospital privacy training treats death as an endpoint. It is not one, and release-of-information staff handling estate requests are operating inside a live regulatory obligation that many organizations have never audited.

“Regulation covers the beginning of decedent care and the paperwork at the end. The custody in the middle — where the person actually is — belongs to whoever the organization decides owns it. Usually nobody has decided.”

It is instructive to look at what happens where a regulator does exist. In the United Kingdom, hospital mortuaries are licensed and inspected. Even under that regime, mortuaries reported dozens of major incidents in a single year, including multiple cases of the wrong body released to funeral directors or families, cases of families shown the wrong person, accidental damage to remains, consent failures, and unauthorized access to a mortuary. That is the failure rate with an inspector. The United States has no equivalent body, no equivalent licensing, and — critically — no equivalent public incident data, which means no U.S. hospital can benchmark its decedent care performance against anything.


Failure Points

Where Decedent Care Breaks: Six Failure Points

Identity. Custody. Evidence.

Across 200+ certification and surveillance audits attended in regulated environments over 28 years, MSI has found that custody failures cluster in predictable places. Applied to decedent care, six stand out.

1. Identity rests on a single unverified act

One person applies the tag. Every subsequent step trusts it. If the tag is wrong at minute one, nothing downstream is designed to detect the error — the funeral home, the crematory, and the family are all reading the same tag. Any identity control that is verified only once, by one person, at the point of creation, is a single point of failure carrying a chain of consequences behind it.

2. Release is verified by paperwork rather than by the person

At the release handoff, the receiving party signs a form attesting that the individual in the bag is the individual named. In practice the bag is often not opened, and the attestation reflects the paperwork rather than an independent check. A verification that confirms the record against the record, rather than the record against the person, is not a verification. This is the exact failure the Rhode Island case turned on, and the complaint alleges the bag was never opened at all.

3. Nothing reconciles in against out

Most morgues keep a log of arrivals and a log of releases. Far fewer perform a periodic reconciliation of one against the other, signed by someone who does not work in the morgue. Without that reconciliation, decedent care has an inventory with no cycle count — and every discrepancy is discovered by an outsider, which is the most expensive way to discover anything.

4. Personal effects have no owner

Rings, phones, wallets, dentures, hearing aids, religious items. Effects move between nursing, security, and the morgue, frequently with an inventory form that is completed by one person and reconciled by none. MSI client experience suggests that when organizations first examine this, the effects process is the least documented step in the entire decedent care pathway and the one that generates the most family complaints per incident.

5. External providers are engaged without control

Funeral homes, crematories, transport services, and anatomical donation programs are external providers under any harmonized management system standard, yet they are rarely evaluated, rarely carry documented requirements, and rarely return confirmation of receipt. The obligation to the family does not transfer when the vehicle leaves the dock. MSI's guidance on purchasing and supplier control and on why supplier management programs fail in year two both turn on the evaluation record functioning as an approval gate rather than a formality.

6. The process has no data, so it has no voice

No indicator, no trend, no committee slot. A process that produces no data cannot compete for resources, cannot demonstrate improvement, and cannot escalate a near miss. Decedent care is usually invisible in the quality report until the day it is on the front page, and by then the only available response is the one the Rhode Island hospital gave: a review, a termination, and a promise of additional safeguards.

Build the procedure before you need it

MSI's ISO 7101:2023 Procedure Templates and Guides cover the controls this pathway depends on — operational planning and control, external provider control, document and records control, internal audit, and management review — written as working documents with the decisions already made, not clause restatements. Editable Microsoft Word, built for quality and clinical governance leads implementing a healthcare quality management system.

See the ISO 7101 Procedure Templates →


The Structural Reason

Why Decedent Care Sits Outside Most Quality Management Systems

Scope. Customer. Silence.

Direct Answer

Decedent care falls outside most hospital quality management systems for three reasons: the scope statement was written around patient outcomes and the patient has died; the service user changes from patient to family and no system named the second one; and the pathway produces no indicator, so it never reaches a committee. None of those is a clinical failure. All three are scope and governance decisions that a management system can correct deliberately.

Scope is where it starts. Every management system standard requires the organization to determine the boundaries and applicability of its system, and every scope decision that excludes something is a decision somebody made — usually by omission. When a hospital scopes its quality system around clinical service lines, decedent care falls into the space between departments and is never claimed. It is not that anyone judged it low risk. It is that nobody was asked.

The customer change is the deeper problem, and it is the reason ordinary quality tooling does not reach here. Patient experience instruments survey patients. Clinical registries measure outcomes. Both go quiet at the moment when decedent care begins, because the person they were built to represent is no longer available to represent themselves. Everything that follows is owed to a family acting as proxy, and to the decedent's own stated wishes recorded in a donation registry, an advance directive, or a religious observance. MSI's work on the patient experience procedure makes the general version of this argument: a satisfaction score is not a management system, and the promise made to a person is a requirement whether or not an instrument measures it.

The silence completes the loop. Because decedent care produces no indicator, it generates no trend, so leadership never reviews it, so no resources are allocated, so no measurement is built. Organizations typically report that the first time decedent care appears in a management review is after an event. MSI's guidance on what a management review record must actually prove covers this pattern in its general form — the vanishing input that everyone assumes someone else brought.

This pattern is not unique to hospitals. The failure of custody controls in an unregulated corner of a prestigious institution is the same pattern MSI examined in the analysis of management system oversight and the Harvard morgue case, where a university's anatomical gift program operated for four years without reconciliation, without an audit objective, and without leadership visibility. Decedent care in a hospital is the same shape of risk, closer to home, and occurring several times a week.


The Opportunity

What ISO 7101 Adoption Would Give Decedent Care

Dignity. Scope. Proof.

Direct Answer

ISO 7101 adoption gives decedent care four things it currently lacks: a scope that includes it, a named service user in the family and the decedent's stated wishes, dignity and respect as system requirements an auditor can sample evidence against, and a governance route that carries custody data to leadership. ISO 7101:2023 is the first international consensus standard for healthcare quality management, and almost no U.S. organization has implemented it — which makes this an early-mover position rather than a remediation.

Take the four in order, because the case has to be made honestly rather than enthusiastically. A standard is not a control, and adopting one does not by itself prevent anything.

A scope that reaches the whole organization

ISO 7101 asks a healthcare organization to define the boundaries of its healthcare quality management system and then to include what falls inside them. Implementation forces the scoping conversation that never otherwise happens, and once it happens, excluding decedent care requires someone to justify the exclusion in writing. In MSI's experience the exclusion never survives being written down, because the person asked to sign it immediately recognizes the exposure. That single conversation is worth more than most of the documentation that follows it.

A named service user when the patient cannot speak

This is the distinctive contribution and it has no equivalent in ISO 9001. ISO 7101 builds the system around people-centred care with respect, compassion, equity, and dignity, and makes service user focus a top-management duty. In decedent care that resolves the customer-change problem directly: the family becomes a named service user whose needs and expectations must be determined, and the decedent's own recorded wishes become a requirement rather than a preference. Everything downstream — verification, effects, communication, timeliness — inherits a defensible reason to exist.

Dignity as something an auditor can sample

The reasonable objection is that dignity cannot be audited. It cannot be graded as a feeling, but it produces artifacts, and artifacts are sampleable: a two-person identity verification record, an effects inventory signed on both sides, a documented viewing offered and its outcome, a timeliness measure from death to release, a complaint from a family and what changed as a result. MSI made the same argument about auditing an abstract requirement in its treatment of auditing quality culture under ISO 9001, and the method transfers exactly. You do not audit the value. You audit the evidence the value produces.

A governance route to the board

ISO 7101 carries the harmonized performance evaluation and improvement architecture at Clauses 9 and 10 — monitoring and measurement, internal audit, management review, nonconformity and corrective action. Adoption gives decedent care a standing route from a morgue reconciliation exception to a leadership decision, which is the mechanism that has been missing. ANSI holds the secretariat for ISO/TC 304, the committee that developed the standard with contributions from around thirty nations.

There is a market argument too, and it is not small. Donation depends entirely on public trust, families increasingly research providers, and no U.S. hospital currently holds a recognized international certification for healthcare quality management. An organization that adopts ISO 7101 and can evidence decedent care inside its scope is claiming a position nobody else in the country holds. MSI's overview of ISO 7101 healthcare quality consulting sets out the founding partner approach, and the practical starting points are covered in key steps for immediate action, patient safety and operational efficiency outcomes, and the service user focus requirement.


Start Here

Eight Decedent Care Controls to Build Before Any Certificate

Cheap. Fast. Defensible.

Most readers are running an ISO 9001 system, an accreditation program, or neither, and are not going to start an ISO 7101 implementation this quarter. Every control below stands on its own, costs almost nothing, and becomes evidence later if adoption follows.

1. Name one process owner for the whole pathway

One person accountable from pronouncement to release, with authority across the departments involved. Everything else fails without this, and it is a decision rather than a project.

2. Two-person identity verification at tagging

The same discipline already applied to blood administration, against an independent identifier rather than against the tag being created. Both names recorded.

3. Verification against the person at release

The bag is opened, the identifier on the person is checked, and both the releasing and receiving parties sign that this specific check occurred. A form attesting to the paperwork is not a control on decedent care; a form attesting to a physical check is.

4. Weekly reconciliation by someone outside the morgue

Arrivals against releases against current occupancy, signed and dated, exceptions explained. This is the single highest-value control in decedent care and it takes fifteen minutes.

5. A real effects chain of custody

Itemized inventory at collection with two signatures, sealed transfer, countersigned release to the family. Valuables handled the way the pharmacy handles a controlled substance, because the emotional value is unrecoverable in a way money is not.

6. Documented requirements for external providers

Written expectations issued to every funeral home, crematory, transport service, and donation program, an evaluation record for each, and a confirmation of receipt returned to the hospital. MSI's guidance on supplier control covers the evaluation record that functions as a gate.

7. Four indicators, reported quarterly

Reconciliation exceptions, hours from death to release, effects discrepancies, and family complaints relating to decedent care. Four numbers give the pathway a voice it has never had.

8. One internal audit objective per year

Written as a question with a numeric answer, not as a document check. MSI's recommended order for building procedures puts roles, document control, and audit early precisely so controls like these have somewhere to live.


Audit

How to Audit Decedent Care Under ISO 19011:2026

Objective. Sample. Number.

ISO 19011:2026 was published on 27 May 2026 and withdrew the 2018 edition immediately, with no transition period. Its most consequential change for a pathway like this is that every audit now carries an explicit objective alongside its scope and criteria. Scope says where to look. Criteria say what to measure against. The objective says what the audit is trying to learn — and that is the difference between confirming a decedent care procedure exists and finding out whether it works.

A document-check audit of this pathway passes. There is a procedure. Staff are trained. Records are retained. An objective-led audit asks something answerable: of the last hundred decedents released, how many carry a release record signed by two parties attesting to a physical identity check, and how many carry only a paperwork attestation? The answer is a percentage. MSI's breakdown of the six edits ISO 19011:2026 requires in an internal audit procedure works through how objectives change what a report can deliver, and internal audit planning covers ranking audit intensity by consequence of failure rather than by ease of evidence gathering — which is exactly why decedent care has been skipped.

Three further objectives worth running in the first cycle. Whether effects inventories reconcile between collection and release for a sampled month. Whether every external provider holding a decedent in the last quarter has a current evaluation record on file. And whether reconciliation exceptions from the last twelve months were closed with verified effectiveness rather than closed on assurance — the distinction MSI treats in internal audit follow-up and in the corrective action procedure.

One caution specific to this area. The 2026 edition strengthens guidance on digital evidence and remote auditing, and decedent care is one of the processes that does not survive being audited from a desk. The log will reconcile on screen. Whether the tag on the person matches the log is a question that requires walking to the morgue with the register in hand.


Leadership

Getting Decedent Care Onto the Management Review Agenda

Input. Trend. Decision.

Direct Answer

Add decedent care as a standing management review input with four elements: reconciliation exceptions with trend, external provider performance and evaluation currency, family complaints relating to the pathway and their disposition, and audit findings with verified closure. Assign each an owner who reports it whether or not there is anything to report. A process with a permanent seat at the leadership table cannot become invisible again.

The reason to formalize this rather than raise it informally is that leadership review is where a management system either proves it saw a risk or proves it did not. In the litigation that followed the Harvard case, the absence of supervision records was itself the evidence that defeated the institution's legal defense. A management review record showing that decedent care custody was examined, discussed, and resourced is a materially different position from a record that never mentions it.

Add one further standing input while the agenda is open: external events. Regulatory actions, court decisions, and published incidents at other organizations, each with an owner required to state whether the same failure could occur here and what evidence supports the answer. ISO 9001 Clause 10.2 asks whether a nonconformity could occur elsewhere, and that phrase is what converts another hospital's front-page week into your control. It costs twenty minutes a quarter, and it is the cheapest form of insurance any decedent care program can buy.

Give the review a record that proves it happened

MSI's ISO Management Review Tool Kits supply the agenda, input pack, slide deck, and minutes format that produce a defensible leadership record — clause by clause across ISO 9001, ISO 13485, ISO 14001, ISO 45001, and ISO 7101. Built from 200+ audits attended, so the inputs registrars actually sample are already in the template.

See the ISO Management Review Tool Kits →


Questions

Decedent Care and ISO 7101: Frequently Asked Questions

Asked. Answered. Sourced.

What is decedent care in a hospital?

Decedent care is the full pathway from pronouncement of death to the point the person leaves the hospital: documentation of death, notification of next of kin, organ procurement organization referral, family viewing, device removal, identification tagging, personal effects handling, morgue custody, autopsy where applicable, death certificate completion, identity verification at release, and handoff to a funeral home, crematory, or donation program. It typically crosses six or more departments and several external providers.

Is decedent care regulated in the United States?

Only partially. The Medicare Condition of Participation at 42 CFR 482.45 requires hospitals to hold an OPO agreement and notify the OPO of every death and imminent death, with parallel duties for critical access hospitals at 485.643, and HIPAA protects the decedent's health information for fifty years after death. Between those points — custody, identification, effects, and release — no federal standard governs decedent care, and no national incident data exists against which a hospital could benchmark itself.

How does ISO 7101 adoption help decedent care specifically?

ISO 7101 adoption forces a scope decision that brings the pathway inside the quality system, names the family and the decedent's stated wishes as service user requirements, makes dignity and people-centred care system obligations that produce sampleable evidence, and supplies the Clause 9 and 10 architecture — monitoring, internal audit, management review, corrective action — that carries a decedent care custody exception up to a leadership decision. No standard prevents an incident on its own; what adoption changes is how quickly one is detected and how defensibly it is handled.

Has any U.S. hospital implemented ISO 7101?

Almost none. ISO 7101:2023 is the first international consensus standard for healthcare quality management and U.S. adoption remains at a very early stage, which is precisely why it represents an opportunity rather than a compliance burden. An organization that adopts it and can evidence decedent care inside its scope is claiming a position essentially no other U.S. provider currently holds — a genuine differentiator with families, payers, and partners.

Who is the service user once the patient has died?

The family or personal representative acting as proxy, together with the decedent's own recorded wishes — donation registration, advance directive, religious observance, or anatomical gift agreement. This customer change is why ordinary patient experience tooling never reaches decedent care: the instruments survey patients, and the obligation after death is owed to someone the system never named. ISO 7101 resolves this by making service user focus a top-management duty rather than a survey.

Can dignity really be audited?

Not as a feeling, but reliably through the artifacts it produces. Auditable evidence in decedent care includes two-person identity verification records, countersigned effects inventories, documented viewing offers and outcomes, time-from-death-to-release measures, external provider confirmations of receipt, and family complaints traced to a change. The method is the same one used for auditing quality culture: audit the evidence the value produces, not the value.

Are funeral homes and crematories external providers under ISO?

Yes. Funeral homes, crematories, transport services, and anatomical donation programs all meet the definition of externally provided processes, products, or services under the harmonized standards, which means documented requirements, evaluation records, and control proportionate to risk. The obligation a hospital owes a family does not transfer when the vehicle leaves the dock, so decedent care control has to extend to a returned confirmation of receipt.

What should we measure first?

Four indicators cover most of the risk: reconciliation exceptions between arrivals and releases, hours from death to release, effects discrepancies, and family complaints relating to the pathway. Report them quarterly with an owner. Organizations typically report that giving decedent care four numbers is what finally allows it to compete for attention and resources, because a process producing no data cannot escalate a near miss.

What is the fastest test of our current controls?

Pull the last fifty release records and count how many document a physical identity check against the person rather than an attestation to the paperwork. Then walk to the morgue with the register and verify current occupancy line by line. Both take an afternoon and both produce a number. MSI runs this as an independent internal audit, or a planning session at 760-434-9141 will scope the decedent care work in a single call.

Be among the first U.S. organizations to hold ISO 7101

MSI is taking founding partner engagements with healthcare organizations ready to build the first U.S. healthcare quality management systems under ISO 7101 — bringing 28 years, 80+ certifications supported, 200+ audits attended, and 600+ professionals trained to a standard almost nobody has implemented yet. We start with how care is actually delivered, including the pathways most quality systems never scoped.

Call 760-434-9141 for a planning session, or explore ISO 7101 healthcare quality consulting, the full ISO Procedure Templates and Guides library, independent internal audits, MSI's ISO consulting, SurePath turnkey certification, and the SureResults maintenance program.

Talk to Us About a Founding Partner Engagement →

Keep Reading

Related Reading on Decedent Care and Healthcare Quality

Deeper. Adjacent. Practical.

References and Sources

eCFR — 42 CFR 482.45, Condition of participation: Organ, tissue, and eye procurement

eCFR — 42 CFR 485.643, the critical access hospital equivalent

CMS — Guidance on OPO agreements with hospitals

Cornell Legal Information Institute — 42 CFR 482.45 annotated text

U.S. Department of Health and Human Services — HIPAA and the health information of deceased individuals

ISO — ISO 7101:2023 healthcare organization management and ISO 19011:2026 guidelines for auditing management systems

ANSI — Inside ISO 7101 and the work of ISO/TC 304

ISO — ISO 20387 biobanking, and ANAB — ISO 20387 accreditation in the United States

The Boston Globe — Reporting on the Rhode Island release error and resulting lawsuit

WPRI Target 12 — Hospital statement and funeral director account of the verification process

Law & Crime — Complaint detail on the release and identification failure

U.S. Department of Justice — Sentencing in the Harvard anatomical gift program case

ASQ — ISO 19011 guidelines for auditing management systems

Global Accreditation Cooperation — accreditation landscape following the January 2026 merger

About Management Systems International (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

msi-international.com  ·  760-434-9141  ·  Veteran-owned and female-owned.

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 15 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply