ISO Compliance · All Five Standards
By Diana Lynn, President and Principal ISO Consultant, MSI · Updated October 4, 2026
QMS compliance is a management system meeting its own requirements and its ISO standard every day, proven by current records rather than a certificate. A certificate is a photograph taken on audit day. QMS compliance is the live feed, and in MSI’s experience most organizations never check whether the camera is still recording.
That gap is why so many people search for the meaning of QMS compliance. They hear “compliant” and “certified” used as if they were the same word. Many also believe that following their procedures makes them compliant. It does not, unless the system is also auditing itself. The internal audit is one of the requirements, and it is the one companies most often miss without realizing it.
They are not. One is a condition you either sustain or lose between visits. The other is an accredited third party’s written opinion about that condition on specific dates.
This guide explains the difference across all five standards MSI implements: ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101. It also gives you a scorecard to test your own system in fifteen minutes. We use “QMS compliance” because it is the phrase most people search, but the same test applies to environmental, safety and healthcare management systems.
Direct Answer
QMS compliance means your management system conforms to its own documented requirements and to the ISO standard right now, with records to prove it. Certification is an accredited body confirming that at audit time. Registrars expect every requirement audited internally each year, so without annual internal audits you are not compliant, certified or not.
Key Takeaways
- QMS compliance is a continuous state; ISO certification is a periodic, independent verification of that state.
- ISO 9001:2026 Clause 3.15 defines conformity as the fulfilment of a requirement, and notes that “conformance” is a deprecated synonym.
- ISO 9001, 13485, 14001, 45001 and 7101 all require internal audits at planned intervals and a management review by top management.
- Accredited certification bodies must audit every certified client at least once each calendar year, and each surveillance visit reviews internal audits and management review.
- Registrars expect every requirement of the standard to be internally audited each year; an organization that skips internal audits is not compliant, even if its procedures are followed and its certificate is current.
Definitions
What Does QMS Compliance Mean?
Define. Prove. Sustain.
QMS compliance means three things are true at the same time. Your system meets the requirements of the standard. It meets the requirements you wrote for yourself in procedures, policies and objectives. And it is effectively implemented and maintained, not only documented. Those three tests come straight from the purpose of internal audit in ISO 9001:2026 Clause 9.2.1, which asks whether the system conforms to the organization’s own requirements and the standard’s requirements, and whether it is effectively implemented and maintained.
Notice what ISO itself calls this. The standards use “conformity,” not “compliance,” when they talk about meeting their own requirements. ISO 9001:2026 defines conformity as fulfilment of a requirement and labels “conformance” a deprecated term.
ISO reserves “compliance” for something narrower. In ISO 14001:2026 Clause 3.2.9, compliance obligations are legal requirements an organization has to comply with and other requirements it has to or chooses to comply with. ISO 45001 uses the parallel idea of legal requirements and other requirements.
So when a quality manager says “QMS compliance,” the precise meaning is conformity of the management system, plus fulfilment of any legal, regulatory, customer or voluntary obligations the system has taken on. Most people use the everyday word, and that is fine. What matters is that both halves need evidence. MSI’s guide to evaluation of compliance under ISO 14001, ISO 45001 and ISO 7101 covers the legal-obligation half in depth. This article focuses on the management-system half, which lives or dies on internal audit.
| Term | Where ISO defines or uses it | What it means in practice |
|---|---|---|
| Conformity | ISO 9001:2026 Clause 3.15 | Fulfilment of a requirement of the standard or of your own system |
| Nonconformity | ISO 9001:2026 Clause 3.16 | Non-fulfilment of a requirement, including your own scheduled audits |
| Compliance obligations | ISO 14001:2026 Clause 3.2.9 | Legal requirements and other requirements you must or choose to meet |
| Legal and other requirements | ISO 45001:2018 Clause 6.1.3 | OH&S obligations the system must determine, access and evaluate |
| Applicable regulatory requirements | ISO 13485:2016 Clause 8.2.4 | Regulatory criteria an internal audit must cover in a device QMS |
| Certification | ISO Certification guidance | Written assurance from an independent body that a system meets requirements |
Compliance vs Certification
QMS Compliance vs Certification: What Is the Difference?
Condition. Confirmation. Credibility.
Direct Answer
QMS compliance is the condition; certification is the confirmation. Compliance is owned by you and must be true every day. Certification is a decision by an accredited body, based on sampled evidence from audits held at least once a calendar year. You can be compliant without a certificate, and certified while quietly drifting out of compliance.
ISO is direct about its own role. On its certification guidance page, ISO explains that it writes standards but does not perform certification or issue certificates. Independent certification bodies do that work. ISO’s overview of management system standards adds that certification is not a requirement, and organizations can benefit from implementing a standard without being certified.
That means certification is optional, but QMS compliance is not optional for anyone who claims to follow a standard. The moment you tell a customer you “follow ISO 9001” or are “ISO compliant,” you have made a claim about conformity.
The only thing that changes with certification is who has checked the claim. MSI tells the story of a firm that lost a bid to an uncertified competitor claiming to be “ISO compliant” in its article on ISO for engineering firms. An unverified compliance claim costs nothing to print. An earned one has records behind it.
| Question | QMS compliance | ISO certification |
|---|---|---|
| Who decides? | Your organization, through internal audit and management review | An accredited certification body |
| How often is it tested? | At the planned intervals you set, and every working day in practice | At least once per calendar year, with recertification every three years |
| What evidence counts? | Audit reports, corrective actions, management review minutes, monitoring records | A sample of that same evidence, reviewed by an external auditor |
| Is it required? | Yes, if you claim to follow the standard | Voluntary, unless a customer, contract or regulator requires it |
| Can it be verified by outsiders? | Only if they ask to see your records | Yes, through the certification body and accredited certificate databases |
| What makes it lapse? | Skipped audits, unclosed actions, missed reviews, unmanaged change | Suspension or withdrawal by the certification body |
Accredited certificates can be checked. ISO’s help center explains how to verify an accredited certification through the certification body or the global certificate database, and the ISO Survey now draws on that same accredited data. MSI explains how that accreditation chain works in its guide to what ISO is and who grants certification and its guide to choosing an ISO registrar. A certificate tells a buyer that someone independent looked. It cannot tell anyone what happened in your system last Tuesday.
“If you are not doing internal audits on an annual basis, you are not compliant.”
— Diana Lynn, President and Principal ISO Consultant, Management Systems International (MSI)
The Internal Audit Test
Why Does QMS Compliance Depend on Annual Internal Audits?
Plan. Audit. Prove.
Direct Answer
QMS compliance depends on internal audits because the internal audit is itself a requirement, not an optional check. Registrars expect every requirement of the standard to be internally audited each year, management review needs the results, and certification bodies review your internal audits every calendar year. No annual internal audit means no compliance.
Here is the blind spot MSI sees most often. A company follows its procedures, ships good product, and passes its last external audit, so it assumes it is compliant. But it has not internally audited its own system in a year or more. That company is not compliant, because internal audit is one of the requirements it agreed to meet.
Across the certification industry, registrars expect every requirement of the standard to be internally audited each year. The standards express the frequency as “planned intervals,” and registrars expect that plan to cover the whole standard every twelve months. In 28 years of implementation and 200+ audits attended, MSI has seen that expectation applied consistently. Three requirements explain why it holds.
1. Your audit program turns your schedule into a requirement
ISO 9001:2026 Clause 9.2.2 requires the organization to plan, establish, implement and maintain an audit program, “including the frequency.” Once you set that frequency, it is one of your own requirements under Clause 9.2.1 a) 1). Missing it is a nonconformity against your own system. The same structure appears in ISO 14001:2026, ISO 45001:2018 and ISO 7101:2023. ISO 13485:2016 Clause 8.2.4 goes further and requires a documented procedure for planning and conducting audits.
2. Management review cannot happen properly without audit results
ISO 9001:2026 Clause 9.3.2 d) 3) lists audit results as a required management review input, and the review itself must happen at planned intervals. If no audit has happened since the last review, that input is empty. A management review with an empty audit input is not a complete review, which means two clauses fail together. MSI’s ISO Management Review Toolkits build that audit-results input into the agenda so the gap is visible before the meeting, not after it.
3. Certification bodies must look at your internal audits every year
Certification bodies operate under ISO/IEC 17021-1. Its surveillance rule requires an audit at least once each calendar year, except in recertification years, as the European co-operation for Accreditation explains in its FAQ on Clause 9.1.3. The accreditation body IAS summarizes the related rule in its ISO/IEC 17021-1 Section 9 overview: each surveillance includes a review of internal audits and management review, and Stage 1 checks whether they are being planned and performed. A year without an internal audit leaves the external auditor nothing to review.
Informative Annex A.9.2 of ISO 9001:2026 adds context, though not a new duty. It explains that internal audit applies to all processes within the QMS, and that audit frequency and scope are influenced by risks and by changes in internal and external issues. Read together, those points describe an audit program that touches every process within a cycle you can defend. Registrars expect that cycle to be twelve months, with every requirement covered. MSI’s guide to internal audit planning under ISO 19011:2026 shows how to build it, and its internal audit risk matrix shows how to weight high-risk processes without leaving others unaudited.
Internal Audit Services · On-Site or Online
We Run Your Internal Audits. Every Requirement, Every Year.
MSI’s independent auditors audit your ISO 9001, 13485, 14001, 45001 or 7101 system against every requirement, on-site or online, and write findings your team can act on. Your twelve-month cycle stays complete, your management review gets real audit results, and your registrar finds a full audit record waiting.
Five Standards, One Principle
How Does QMS Compliance Work Across ISO 9001, 13485, 14001, 45001 and 7101?
Same Structure. Different Stakes.
Every standard MSI implements shares the same backbone for QMS compliance: internal audit at planned intervals, a management review by top management, and corrective action when something fails. The differences sit in what each audit must cover and who else can ask to see the results. The table below is current as of October 4, 2026.
| Standard (current edition) | Internal audit clause | Management review clause | What raises the stakes |
|---|---|---|---|
| ISO 9001:2026 (published Sept 16, 2026) | 9.2 | 9.3 | Objectives, criteria and scope defined for each audit; eight review inputs at 9.3.2 |
| ISO 13485:2016 | 8.2.4 | 5.6 | Audits cover applicable regulatory requirements; documented procedure required; FDA can inspect audit records under the QMSR |
| ISO 14001:2026 (published Apr 15, 2026) | 9.2 | 9.3 | The audit program itself must be available as documented information; evaluation of compliance at 9.1.2 |
| ISO 45001:2018 (with Amd 1:2024) | 9.2 | 9.3 | Relevant audit results reported to workers and their representatives; evaluation of compliance at 9.1.2 |
| ISO 7101:2023 | 9.2 | 9.3 | Audits reach clinical and non-clinical processes alike; service user safety rides on the result |
ISO 9001:2026: per-audit objectives make thin audits visible
ISO 9001:2026 was published on September 16, 2026. Clause 9.2.2 a) requires audit objectives, criteria and scope for each audit, and Clause 9.2.2 d) requires appropriate correction and corrective actions without undue delay. Audits that only confirm a procedure exists will struggle to show a stated objective was met. MSI walks through the full list of revisions in ISO 9001:2026 changes and the most common failure points in internal audit mistakes even seasoned auditors make. For quality teams, the ISO 9001 Procedure Templates and Guides bundle is the fastest way to put a defensible internal audit procedure in place.
ISO 13485: QMS compliance is literally regulatory
In a medical device QMS, Clause 8.2.4 of ISO 13485:2016 requires internal audits to check conformity with planned arrangements, the standard, the organization’s own QMS requirements and applicable regulatory requirements. That last item turns QMS compliance into regulatory compliance. In the United States, the FDA’s Quality Management System Regulation took effect on February 2, 2026 and incorporates ISO 13485 by reference. The FDA’s QMSR frequently asked questions state that the agency now has authority to inspect management review, quality audit and supplier audit reports. MSI covers what that means for device teams in its article on medical device cybersecurity as a QMS issue, and the role that holds it together in the ISO management representative.
ISO 14001:2026: the audit program must be on paper
ISO 14001:2026 was published April 15, 2026, and certified organizations have until April 30, 2029 to transition, as of October 4, 2026. Its Clause 9.2.2 lists the audit program itself among the documented information that must be available, alongside evidence of implementation and results. Clause 9.1.2 separately requires the organization to determine how often compliance obligations are evaluated and to maintain knowledge of its compliance status. An EMS can therefore lapse on two clocks at once. MSI explains how to run both on one plan in the combined ISO 9001 and 14001 transition.
For Experienced EHS Managers
Update Your ISO 14001:2015 System to 2026 in a Week
The ISO 14001:2026 Procedure Templates and Guides were built for experienced EHS managers who already run an ISO 14001:2015 system and need it updated to the 2026 edition in a week’s time. The internal audit procedure carries the documented audit program requirement and per-audit objectives already written in.
ISO 45001: workers see the results
ISO 45001:2018, with Amendment 1:2024, remains the current edition as of October 4, 2026, with a revision underway at ISO. Its Clause 9.2.2 goes beyond reporting to managers. Relevant audit results must also reach workers and, where they exist, workers’ representatives.
That makes a skipped audit visible on the shop floor, not just in the quality office. Combined with legal requirements at Clause 6.1.3 and evaluation of compliance at Clause 9.1.2, an OH&S system carries some of the heaviest evidence load of the five. MSI’s ISO 45001 consulting page shows how the safety layer is built around real hazards.
ISO 7101: healthcare quality needs audit evidence most of all
ISO 7101:2023 is the first international standard for healthcare quality management. It follows the harmonized structure, with internal audit at Clause 9.2 and management review at Clause 9.3.
Healthcare organizations often already live with accreditation surveys, which can make QMS compliance feel redundant. It is not. An internal audit under ISO 7101 tests whether the management system works across scheduling, credentialing, facilities and service user feedback, not only at the bedside. MSI’s ISO 7101 healthcare quality consulting and its analysis of management system oversight explain why that reach matters. The ISO 7101:2023 Procedure Templates and Guides give healthcare teams the internal audit procedure in working form.
Running more than one of these standards? MSI’s editable IMS Internal Audit Procedure Template and Guide covers ISO 9001, ISO 14001:2026 and ISO 45001 in one controlled document, so a single audit program can demonstrate QMS compliance for all three. MSI’s connected quality management model applies the same idea across multiple sites.
Requirement Status
Which QMS Compliance Items Are Requirements and Which Are Recommendations?
Shall. Should. Smart.
A requirement uses “shall.” A NOTE is for consideration only. Annex A is informative and adds no requirements. Rules written for certification bodies bind them, not you. Mixing these up is the fastest way to over-build or under-build a system, so the table labels each item.
| Item | Source | Status |
|---|---|---|
| Conduct internal audits at planned intervals | ISO 9001:2026, 14001:2026, 45001:2018, 7101:2023 Clause 9.2.1; ISO 13485:2016 Clause 8.2.4 | Requirement |
| Maintain an audit program including frequency, methods, responsibilities, planning and reporting | Clause 9.2.2 in the harmonized standards | Requirement |
| Define objectives, criteria and scope for each audit | ISO 9001:2026 and ISO 14001:2026 Clause 9.2.2 a) | Requirement |
| Audit program available as documented information | ISO 14001:2026 Clause 9.2.2 | Requirement |
| Documented procedure for internal audit | ISO 13485:2016 Clause 8.2.4 | Requirement |
| Audit results as a management review input | ISO 9001:2026 Clause 9.3.2 d) 3) and equivalents | Requirement |
| Internal audit applies to all processes; frequency influenced by risk and change | ISO 9001:2026 Annex A.9.2 | Informative Annex A (no added requirement) |
| Internal audits can form the basis for a declaration of conformity | ISO 9001:2026 Clause 3.18, Note 5 to entry | NOTE (consideration only) |
| Audit program schedule, number, duration and frequency | ISO 19011:2026 Clause 5.1 | Guidance (“should”) |
| Surveillance audit at least once per calendar year, reviewing internal audits and management review | ISO/IEC 17021-1 | Requirement on certification bodies, not on your organization |
| Internally audit every requirement and process at least every 12 months | Registrar expectation across the certification industry | Industry expectation; MSI practice |
Original MSI Asset
How Can You Score Your QMS Compliance in 15 Minutes?
Score. Decide. Act.
MSI created the 12-Month QMS Compliance Evidence Scorecard for this article. It turns the requirements above into ten yes-or-no evidence checks you can run with your records open. Score each item 2 if the evidence exists for the last twelve months, 1 if it exists but is incomplete or late, and 0 if it does not exist. It works for ISO 9001, 13485, 14001, 45001 and 7101 systems alike.
| # | Evidence check (last 12 months) | Clause basis | Score 0 to 2 |
|---|---|---|---|
| 1 | Every requirement and process in scope was internally audited | 9.2.1; Annex A.9.2; registrar expectation | |
| 2 | Each audit had written objectives, criteria and scope | 9.2.2 a) | |
| 3 | No auditor audited their own work | 9.2.2 b) | |
| 4 | Results reached relevant managers (and workers, for ISO 45001) | 9.2.2 c) | |
| 5 | Findings were corrected and corrective actions closed without undue delay | 9.2.2 d); 10.2 | |
| 6 | Audit results were presented at a management review | 9.3.2 | |
| 7 | Management review produced recorded decisions on improvement, changes and resources | 9.3.3 | |
| 8 | Legal, regulatory and other obligations were evaluated at your set frequency | 14001 and 45001 9.1.2; 13485 8.2.4 | |
| 9 | Audit program, implementation evidence and results are retained | 9.2.2 | |
| 10 | The audit program was re-planned after changes or poor audit results | 9.2.2 |
Decision rules. A total of 18 to 20 means QMS compliance is current and demonstrable. A total of 13 to 17 means the system is compliant on paper but drifting, and the weakest items need owners and dates. A total of 12 or below means the system is not compliant today. One override applies to every total: a 0 on item 1 or item 6 means you are not compliant, because the audit and review chain is broken.
Scorecard Showed Gaps? · Most Popular
Your Internal Audit Procedure, Already Written
MSI’s ISO Procedure Templates and Guides are finished, editable Word procedures for ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101, annotated from 200+ audits attended. The internal audit procedure, audit schedule and corrective action forms are built to interlock, so QMS compliance has a paper trail from the first audit.
If the scorecard exposes a transition problem as well, pair it with MSI’s free interactive ISO Transition Risk Scorecard for ISO 9001:2026 and ISO 14001:2026.
Drift Between Audits
What Happens When QMS Compliance Lapses Between Certification Audits?
Drift. Detect. Decide.
Systems rarely fail in one dramatic moment. MSI client experience suggests they erode in a predictable order. First the internal audit slips “just one quarter” because of a busy season.
Then the management review is held without audit results, so leadership approves a status that nobody verified. Then corrective actions age because no one is asking about them. By the time the external auditor arrives, procedures still describe a system that people stopped following months earlier.
The cost is not a failed visit. It is the operating problem that the audit would have caught: a supplier whose performance nobody reviewed, a training record that expired, a calibration that lapsed, a legal requirement that changed. Procedures that work in practice catch those problems in-house. Procedures that fail in practice let them reach customers, workers, patients or the environment. MSI makes the same point in its article on the ISO audit as a recurring test of trust, where certification is something you keep earning, cycle after cycle.
“Having systems, acting on what the records are reporting, and never letting anyone deny the facts is what prevents good systems from deteriorating.”
— Diana Lynn, President and Principal ISO Consultant, MSI
Integrity is the thread that runs through all of it. A certificate records a promise, and QMS compliance is how that promise is kept between visits, when no external party is watching. MSI develops that idea in ISO standards and integrity.
Recovery
How Do You Restore QMS Compliance After Missed Internal Audits?
Restart. Review. Recover.
Direct Answer
Restore QMS compliance by holding an “End in Mind” management review using the data you already have, marking missing data TBD with dates, then running a risk-weighted internal audit of every process, closing findings, and feeding results into the next review. Most organizations can rebuild a defensible evidence chain in one cycle.
MSI recommends starting with management review rather than the audit, because review is where leadership commits resources. In an “End in Mind” review, you put every required input on the slides, fill in the data you already hold, and mark missing items TBD with a date and an owner. The gaps become a visible action plan approved by top management, instead of a list the quality manager carries alone. MSI’s management review toolkits are built for exactly that first meeting.
- Hold the “End in Mind” management review. Present every required input, record decisions and resources, and date every TBD.
- Re-plan the audit program by risk. Put the highest-risk and longest-unaudited processes first, with written objectives for each audit.
- Assign impartial auditors. Use trained staff from other departments, or an independent internal auditor if your team is too small to stay objective.
- Audit every process within the cycle. Record findings against the clause and your own procedure.
- Close the findings. Correct, find root causes, and verify that corrective actions worked.
- Close the loop at the next review. Present audit results, action status and decisions, and set the next twelve-month cycle.
For teams that would rather not rebuild audit capability in-house, MSI performs independent internal audits against all five standards, on-site or remotely. MSI’s SureResults ISO maintenance program keeps the twelve-month clock from lapsing by running the audits, supporting management review and preparing registrar visits year-round. Teams building their own auditors can develop the method through MSI’s internal audit skills guidance. MSI’s updated internal auditor courses for the 2026 editions are coming soon, starting with the ISO Internal Auditor Online Workshop.
ISO 9001:2026 Timing
How Does the ISO 9001:2026 Transition Affect QMS Compliance?
Publish. Plan. Transition.
As of October 4, 2026, ISO 9001:2026 is published and ISO 9001:2015 certificates remain valid during the transition. Global ACI, which replaced the IAF and ILAC on January 1, 2026, has set the rules in its transition requirements for ISO 9001:2026. From March 31, 2028, new and initial accredited certifications may only be issued to the 2026 edition. Organizations certified to the 2015 edition have until September 30, 2029 to complete their transition.
For QMS compliance, the practical point is evidence lead time. A transition audit will look for at least one internal audit with per-audit objectives and one management review that carries the 2026 inputs. Neither can be produced the week before the visit. MSI’s guide to ISO transition planning works backward from your next surveillance date, and its ISO 9001:2026 consultant test helps you decide whether outside ISO consulting support is worth it. The ISO 9001 Auditing Practices Group, convened by ISO’s quality committee and the accreditation community, also publishes free guidance papers on internal audit.
Why MSI
Why Does Measurable ISO Consulting Experience Matter for QMS Compliance?
Experience. Evidence. Endurance.
QMS compliance is a judgment about evidence, and judgment improves with exposure. Management Systems International (MSI) has 28 years of ISO consulting behind that judgment, with 80+ certifications supported, 200+ audits attended and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare and other regulated industries. MSI is veteran-owned and female-owned, and it attends certification audits alongside its clients rather than handing over documents and leaving.
That experience is why MSI’s ISO consulting work starts with how your people actually work, then writes procedures that match. A procedure that matches real work is one people follow, and a followed procedure is the cheapest form of QMS compliance there is. For organizations building a system from the beginning, MSI’s SurePath turnkey certification program builds the internal audit program from day one. You can learn more about MSI’s approach on the ISO consulting page, or watch the free ISO Executive Decision Briefs for a leadership-level view of what each standard asks of top management.
Next Steps
What Is the Fastest Path to Demonstrable QMS Compliance?
Choose. Click. Comply.
If you scored below 18, start with option 1. Pick the option that matches where your scorecard landed. Each one leads directly to the resource or conversation that closes that gap.
1 · Audits have lapsed or never started
Let MSI Perform Your Internal Audits, On-Site or Online
Independent, objective-led internal audits covering every requirement of ISO 9001, 13485, 14001, 45001 or 7101. Choose a one-time audit to restore QMS compliance now, or SureResults to keep the twelve-month cycle on schedule year after year.
2 · Need the documents
Stop Writing Procedures From Scratch
Finished, editable procedures for all five standards, with the internal audit, corrective action and management review procedures already linked so the evidence chain holds together.
3 · Quality system on ISO 9001
The Complete ISO 9001 Procedure Set
Every ISO 9001 procedure in working form, including an internal audit procedure that schedules every process and records objectives for each audit.
4 · Environmental system on ISO 14001
Move Your ISO 14001:2015 EMS to 2026 in a Week
Built for experienced EHS managers updating an existing ISO 14001:2015 system to the 2026 edition in a week’s time, with the documented audit program, per-audit objectives and evaluation of compliance already written in.
5 · Management review is overdue
Run a Decision-Ready Management Review This Month
Clause-by-clause presentation decks and minutes forms for ISO 9001:2026, 13485, 14001:2026, 45001 and 7101, so audit results and every other required input reach leadership with an owner attached.
6 · Not sure where you stand
Book a 30-Minute Planning Session
Bring your scorecard total. An MSI consultant will tell you which items to fix first and what a realistic recovery timeline looks like. Call 760-434-9141.
FAQ
QMS Compliance: Frequently Asked Questions
Ask. Answer. Act.
What does QMS compliance mean?
QMS compliance means a management system meets its own documented requirements and the requirements of its ISO standard, and is effectively implemented and maintained, with current records to prove it. ISO's precise word for this is conformity, defined in ISO 9001:2026 Clause 3.15 as fulfilment of a requirement.
Is QMS compliance the same as ISO certification?
No. QMS compliance is a condition your organization must sustain every day. ISO certification is an accredited certification body's written confirmation of that condition, based on audits held at least once per calendar year. You can be compliant without being certified, and certified while drifting out of compliance between visits.
Can a company be ISO compliant without being certified?
Yes. ISO states that certification to its management system standards is not a requirement. A company can achieve QMS compliance without a certificate, but the claim is unverified unless it can show internal audit reports, management review records and closed corrective actions on request.
How often must internal audits be done for QMS compliance?
At least annually, covering every requirement. Registrars across the certification industry expect each requirement of the standard to be internally audited every year, and they review internal audits at every surveillance visit. A company that follows its procedures but skips internal audits does not have QMS compliance.
Does an ISO certificate prove QMS compliance today?
Not by itself. A certificate shows that an accredited body found the system conforming on the dates it audited. QMS compliance today is shown only by current evidence: recent internal audits, a management review within its planned interval, and corrective actions closed without undue delay.
Do ISO 13485, 14001, 45001 and 7101 have the same internal audit requirement as ISO 9001?
All five require internal audits at planned intervals, so QMS compliance rests on the same principle. The details differ: ISO 13485 Clause 8.2.4 adds applicable regulatory requirements and a documented procedure, ISO 14001:2026 requires the audit program to be documented, and ISO 45001 requires relevant results to reach workers.
How quickly can QMS compliance be restored after missed internal audits?
Most organizations can rebuild a defensible QMS compliance evidence chain within one audit cycle. MSI recommends starting with an End in Mind management review that marks missing data TBD with dates, then auditing every process by risk, closing findings, and presenting the results at the next review.
Does ISO 9001:2026 change QMS compliance requirements?
ISO 9001:2026, published September 16, 2026, keeps internal audit at Clause 9.2 and requires objectives, criteria and scope for each audit. For QMS compliance during transition, plan at least one internal audit and one management review carrying the 2026 inputs before your transition audit; certified organizations have until September 30, 2029.
References and Sources
- ISO 9001:2026, Quality management systems — Requirements, Clauses 3.15, 3.16, 3.18, 9.2, 9.3 and Annex A.9.2 (licensed text).
- ISO 14001:2026, Environmental management systems — Requirements with guidance for use, Clauses 3.2.9, 9.1.2 and 9.2 (licensed text).
- ISO 19011:2026, Guidelines for auditing management systems, Clause 5.1 (licensed text).
- ISO — Certification
- ISO — Management system standards
- ISO Help — Does ISO carry out certification?
- ISO Help — How to verify an accredited certification
- ISO — The ISO Survey
- Global ACI — Transition requirements for ISO 9001:2026
- European co-operation for Accreditation — FAQ on ISO/IEC 17021-1 Clause 9.1.3
- IAS — ISO/IEC 17021-1 Section 9 process requirements
- U.S. FDA — Quality Management System Regulation FAQ
- ISO 45001:2018 — Occupational health and safety management systems
- ISO 7101:2023 — Management systems for quality in healthcare organizations
- ISO/TC 176 — ISO 9001 Auditing Practices Group
About Management Systems International (MSI)
Diana Lynn, President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI’s early years, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.
Veteran-owned · Female-owned · About MSI · msi-international.com · 760-434-9141
