ISO 9001:2026 · ISO 14001:2026 · Transition Strategy
By Diana Lynn, President and Principal ISO Consultant, MSI · Updated October 1, 2026
An ISO transition risk assessment is a scored review of what could delay moving ISO 9001 and ISO 14001 certificates to their 2026 editions.
Here is the part most transition coverage skips. Your two certificates are running on two different clocks, and the environmental clock started five months before the quality clock. If you operate more than one site, every site rides on the weakest one. And if your quality and environmental certificates sit with different registrars, you may not yet know whether both registrars will even be accredited to issue 2026-edition certificates on the dates you are counting on.
None of that is a reason to worry. It is a reason to measure. An ISO transition risk assessment turns a vague sense of “we have until 2029” into a dated, site-by-site, registrar-by-registrar plan that leadership can approve and every department can follow. Procedures that work in practice come from plans like that, not from a scramble in the final year. This guide shows how to perform one, and MSI's free ISO Transition Risk Scorecard lets you run it online in about five minutes.
Direct Answer: An ISO transition risk assessment scores the timing, multi-site and multi-registrar factors that affect your ISO 9001:2026 and ISO 14001:2026 transitions, then picks an audit route and start date for each certificate. Both transitions must be complete by September 30, 2029 and April 30, 2029, respectively.
Key Takeaways
- ISO 14001:2015 certificates are no longer valid after April 30, 2029, and ISO 9001:2015 certificates are no longer valid after September 30, 2029, under Global ACI's mandatory transition requirements (as of October 1, 2026).
- From October 31, 2027, new ISO 14001 certifications may be issued only to the 2026 edition; for ISO 9001 that date is March 31, 2028.
- Under IAF MD 1, an open major nonconformity at any one site holds the certification decision for the whole multi-site organization until corrective action is satisfactory.
- A registrar that decides not to transition its ISO 14001 accreditation must tell its clients in writing by January 31, 2027.
- ISO 9001:2026 Clause 7.3 e) requires every person doing work under the organization's control to be aware of its quality culture and ethical behaviour, not only top management.
- The free MSI ISO Transition Risk Scorecard rates ten factors from 1 to 3 for each certificate and converts the total into an audit route and a recommended start date.
Section 1 · The Concept
What Is an ISO transition risk assessment and Why Does It Matter Now?
Score. Sequence. Succeed.
An ISO transition risk assessment applies the risk thinking both standards already require to the transition itself. ISO 9001:2026 Clause 6.1.2 requires the organization to determine, analyse and evaluate risks that can have an undesired effect on its ability to provide conforming products and services. ISO 14001:2026 Clause 6.1.4 requires the risks and opportunities that need to be addressed to be available as documented information. A transition with fixed external deadlines is exactly the kind of external issue those clauses were written for.
What makes 2026 unusual is the overlap. ISO 14001:2026 published on April 15, 2026, and ISO 9001:2026 published on September 16, 2026. For the roughly 700,000 accredited ISO 14001 certificates Global ACI counts, and the more than one million accredited ISO 9001 certificates, the transition windows overlap for most of their length but close five months apart. Dual-certified organizations therefore face two deadlines, two sets of registrar readiness dates and, often, two different points in two certification cycles.
The risk is rarely the standards themselves. Global ACI describes the ISO 14001 changes as minimal and largely intuitive, and it describes the ISO 9001 revision as updates intended to improve clarity and usability. The real exposure sits in scheduling: whether the revised system has run long enough to produce records, whether every site can show it, and whether each registrar is ready when you need it. That is why an ISO transition risk assessment focuses on timing, sites and registrars before it looks at clause-by-clause document edits, which MSI covers separately in its guide to running one ISO 9001 and 14001 transition plan.
Opportunity belongs in the same exercise. ISO 9001:2026 separated opportunities into Clause 6.1.3, and the transition itself is a circumstance that can produce beneficial effects, as MSI explains in its article on opportunity-based thinking. Consolidating registrars, aligning audit dates or finally integrating two systems are all opportunities an ISO transition risk assessment can surface alongside the risks.
Section 2 · The Dates
What Are the ISO 9001:2026 and ISO 14001:2026 Transition Dates?
Date. Plan. Deliver.
Transition dates come from Global ACI, the body that assumed the former roles of the International Accreditation Forum and the International Laboratory Accreditation Cooperation on January 1, 2026. Its transition requirements are mandatory for every accreditation body signatory to the Global ACI Multilateral Recognition Arrangement and the certification bodies they accredit. The table below reflects Global ACI TECH-3-TR 2029-09-30 (M) for ISO 9001:2026 and Global ACI TECH-3-TR 2029-04-30 (M) for ISO 14001:2026, as of October 1, 2026.
| Milestone | ISO 14001:2026 | ISO 9001:2026 |
|---|---|---|
| Standard published | April 15, 2026 | September 16, 2026 |
| Accreditation bodies ready to assess | October 31, 2026 | March 31, 2027 |
| Registrars submit transition declarations | January 31, 2027 | June 30, 2027 |
| Accreditation body transition decisions complete | April 30, 2027 | September 30, 2027 |
| New and initial certifications only to the 2026 edition | From October 31, 2027 | From March 31, 2028 |
| Transition complete; 2015 certificates no longer valid | April 30, 2029 | September 30, 2029 |
Two dates matter more than the headline deadlines for an ISO transition risk assessment. The first is when your own registrar's accreditation actually transitions, because a registrar cannot issue an accredited 2026-edition certificate before its accreditation body has made that decision. The second is the date of your last scheduled audit before each deadline, because that is the latest point at which a transition can be folded into an audit you are already paying for. MSI's article on the ISO 2026 transition deadline works through the calendar math in more detail, and the ISO transition planning calendar turns it into milestones.
Direct Answer: For an ISO transition risk assessment, ISO 14001 comes first: the 2015 edition stops being valid after April 30, 2029, and new 2015-edition certificates end October 31, 2027. ISO 9001:2015 certificates remain valid until September 30, 2029, with new certificates issued only to ISO 9001:2026 from March 31, 2028.
October 31, 2026
Accreditation bodies must be ready to assess ISO 14001:2026. Ask each registrar for its written transition arrangement.
January 31, 2027
Deadline for an ISO 14001 registrar that will not transition to notify its clients in writing.
Spring–Autumn 2027
Registrar accreditation decisions land for both standards. Confirm yours before booking transition audits.
October 31, 2027 / March 31, 2028
Last dates for new 2015-edition certificates: ISO 14001 first, then ISO 9001.
April 30, 2029 / September 30, 2029
Transition complete, including certificate issuance, for ISO 14001 and then ISO 9001.
Section 3 · The Requirements
Which Clauses Support an ISO transition risk assessment?
Clause. Evidence. Confidence.
No clause in either standard uses the phrase “transition risk assessment,” and MSI never presents it as a stand-alone requirement. What the standards do require is planned change, determined risks and opportunities, an audit program that considers changes, and a management review that decides on changes and resources. An ISO transition risk assessment is simply the most efficient way to meet those requirements for this particular change. The table separates what is required from what is guidance and what is MSI's recommendation.
| Item | Source | Status |
|---|---|---|
| Determine, analyse and evaluate risks to conforming output | ISO 9001:2026 Clause 6.1.2 | Requirement |
| Determine and address opportunities | ISO 9001:2026 Clause 6.1.3 | Requirement |
| Carry out QMS changes in a planned manner, considering purpose, integrity, resources, responsibilities, communication and effectiveness | ISO 9001:2026 Clause 6.3 a)–g) | Requirement |
| Risks and opportunities to be addressed available as documented information | ISO 14001:2026 Clause 6.1.4 | Requirement |
| Carry out EMS changes in a planned manner (elevated to its own clause in 2026) | ISO 14001:2026 Clause 6.3 | Requirement |
| Consider changes affecting the organization when establishing the internal audit program; define audit objectives for each audit | ISO 9001:2026 and ISO 14001:2026 Clause 9.2.2 | Requirement |
| Management review results include decisions on changes and resources | ISO 9001:2026 and ISO 14001:2026 Clause 9.3.3 | Requirement |
| Every person doing work under the organization's control aware of quality culture and ethical behaviour | ISO 9001:2026 Clause 7.3 e) | Requirement |
| Ethical behaviour can impact all aspects of quality | ISO 9001:2026 Annex A.5.1 | Informative Annex A (no added requirement) |
| Identify audit program risks such as planning, resources, locations and auditor availability | ISO 19011:2026 Clause 5.3 | Guidance (“should”) |
| Site sampling, central function audits and multi-site certification decisions | IAF MD 1:2023 | Requirement on registrars, not on your organization |
| Transfer of accredited certification between registrars | IAF MD 2:2023 | Requirement on registrars, not on your organization |
| A scored ISO transition risk assessment approved at management review | MSI Transition Risk Scorecard | MSI recommendation |
Two accuracy notes are worth stating plainly. ISO 14001:2026 Clause 6.3 elevated planning of changes to its own clause; the 2015 edition already required control of planned changes in Clause 8.1, so the concept is not new to a mature environmental management system. And NOTES and Annex A text in either standard are for consideration only. They create no obligation, so an ISO transition risk assessment should never turn them into findings or duties.
ISO 19011:2026, which replaced the 2018 edition on May 27, 2026 with no transition period, gives the most practical vocabulary. Its Clause 5.3 lists audit program risks that map almost one-to-one onto transition risks: the extent, number, duration, locations and schedule of audits; insufficient time; lack of competent auditors; and the availability of evidence to be sampled. Teams that already think in those terms find an ISO transition risk assessment familiar territory.
Section 4 · Timing
How Do You Assess Timing Risk Across Two Offset Clocks?
Map. Match. Move.
In an ISO transition risk assessment, timing risk is the gap between when a certificate must transition and when the revised system will have enough operating evidence to show. Global ACI allows three audit routes for both standards: a scheduled surveillance audit, a recertification audit, or a separate special transition audit. Each route has a different cost and a different evidence threshold, so the first job in any ISO transition risk assessment is to place every certificate on its own cycle.
Place each certificate on its cycle
Write down, for each certificate, the issue date, the expiry date and the month of every scheduled audit between now and the relevant deadline. A certificate issued in mid-2026 with a recertification in mid-2029 has two surveillance audits inside the window but a recertification that lands after the ISO 14001 deadline. A certificate recertified in 2027 can absorb the transition at an audit that already includes a full system review, and the Global ACI ISO 14001 document notes that additional audit time may not be needed for a full system audit.
Where the transition is added to a surveillance audit, expect the registrar to consider extra audit time. The ISO 14001:2026 transition requirements direct registrars to decide on additional time based on the degree of change to your system and whether the transition is combined with an annual audit or done as a special audit. Ask for that calculation in writing early, because it affects budget and site-visit planning.
Work backward from the evidence, not forward from today
A registrar transitions a certificate on evidence that the revised system operates: records produced under revised procedures, at least one internal audit run against 2026 requirements, and a management review that receives the results. MSI's article on the ISO 14001:2026 management review explains why the review is the natural governance point for the transition. In practice, that means an ISO transition risk assessment should set the start date by counting backward from the transition audit, allowing for one full internal audit and management review cycle.
Direct Answer: Timing in an ISO transition risk assessment is set backward: choose the audit that will carry the transition, subtract one internal audit and one management review cycle, then subtract the time to update procedures. For most dual-certified organizations, ISO 14001 sets the earlier start date.
Capacity is the other timing factor. Registrars face the same window for more than 1.7 million combined certificates, and the auditor pool is already tight, a pattern MSI described in its analysis of the qualified auditor shortage. MSI client experience suggests that audit dates booked a year ahead are far easier to hold than dates requested in the final two quarters of a transition window.
Section 5 · Multi-Site
How Does an ISO transition risk assessment Change With Multiple Sites?
Central. Sampled. Consistent.
Multi-site certification is governed by IAF MD 1:2023, issued under IAF and now part of the document set Global ACI maintains. Its logic is simple: one management system, controlled by an identified central function, with every site inside the internal audit program and a centralized management review. The registrar audits the central function and a sample of sites, which is where most multi-site transition risk lives.
Sample size and what it means for readiness
For sites performing very similar activities, MD 1 sets the minimum sample as the square root of the number of sites for an initial audit, 0.6 times the square root for each surveillance audit, and the initial figure for recertification, reducible to 0.8 times the square root where the system has proved effective. At least 25% of the sample must be random, and the central function is audited at initial certification, at every recertification and at least once a calendar year.
| Total sites | Initial / recertification | Each surveillance | Reduced recertification |
|---|---|---|---|
| 4 | 2 | 2 | 2 |
| 9 | 3 | 2 | 3 |
| 16 | 4 | 3 | 4 |
| 25 | 5 | 3 | 4 |
| 50 | 8 | 5 | 6 |
Because the random portion means you cannot predict which sites will be visited, every site has to be transition-ready at the same time. Sites that perform different activities may not be eligible for sampling at all; MD 1 then requires all sites at initial and recertification audits and 30% of sites in each surveillance year. If your network mixes both kinds, your ISO transition risk assessment and schedule have to accommodate both.
One site's open issue holds every site's certificate
MD 1 Clause 7.7.1 requires a nonconformity found at one site to be investigated for possible effect on other sites, and Clause 7.7.3 holds the certification decision for the whole multi-site organization while any site has an open major nonconformity. Clause 7.7.4 rules out excluding the site to get around it. For an ISO transition risk assessment, that makes the least-prepared site the pacing item for the entire certificate.
Direct Answer: In a multi-site ISO transition risk assessment, readiness is set by the weakest site, because sampling is partly random and an open major nonconformity at any site holds the certification decision for every listed site. Score the central function and each site separately, then plan to the lowest score.
The practical answer is standardization. One revised procedure set rolled out from the central function, with site-level records proving local use, is far easier to transition than site-specific variants. MSI's guides to multi-site ISO certification, multi-site ISO integration and multi-site procedure standardization cover the architecture; the ISO Procedure Templates and Guides supply a single 2026-edition set that can be deployed to every site at once.
Section 6 · Multi-Registrar
What Happens When Sites or Standards Sit With Different Registrars?
Verify. Align. Transfer.
Multi-registrar exposure is the factor competitors almost never address, and it is common. Acquisitions bring sites certified by a different registrar; quality and environmental certificates were often obtained years apart; and some organizations deliberately split standards between registrars. An ISO transition risk assessment treats each registrar relationship as its own line item, because each registrar transitions on its own accreditation timeline.
Confirm every registrar's transition status
Start the registrar portion of the ISO transition risk assessment by listing every certificate, its registrar, its accreditation body and its scope. Verify each one in CertSearch, the global database of accredited certifications. Then ask each registrar for its written transition arrangement. The ISO 14001 transition requirements are explicit: a registrar that decides not to transition must notify affected clients in writing by January 31, 2027, with information on certificate validity and the consequences of not transferring or transitioning. For registrars that do transition, accreditation bodies must complete their decisions by April 30, 2027 for ISO 14001 and September 30, 2027 for ISO 9001.
Know how a transfer works before you need one
If a registrar will not transition, or if consolidation makes sense, certification can move under IAF MD 2:2023. Only valid accredited certification can be transferred, and certification known to be suspended cannot be accepted. The accepting registrar conducts a pre-transfer review of audit reports and the status of open nonconformities, may add a pre-transfer visit where needed, and will not issue its certificate until outstanding major nonconformities are verified as corrected and plans for minor ones are accepted. Building that into the timeline matters, because a transfer and a transition audit can be combined only if the timing allows it.
Direct Answer: For multiple registrars, an ISO transition risk assessment confirms each registrar's written transition arrangement and accreditation date, verifies every certificate in CertSearch, and decides early whether to align or consolidate. A transfer under IAF MD 2 is straightforward for a valid, unsuspended certificate with no open majors.
Consolidation is a decision, not a default. Integrated audits under IAF MD 11 can reduce total audit time for a combined system, and IAF ID 14 gives registrars guidance on audit time for integrated multi-site systems, but a long relationship with a registrar that knows your operation also has value. MSI's article on choosing an ISO registrar sets out the selection factors. One boundary never moves: under ISO/IEC 17021-1, a registrar cannot provide consultancy to the organizations it certifies, which is why the transition plan itself is your work or your consultant's, as explained in MSI's guide to the ISO 9001:2026 consultant role.
Section 7 · Culture and Ethics
Why Is Quality Culture and Ethical Behavior a Transition Risk in Every Department?
Every. Department. Matters.
ISO 9001:2026 introduced quality culture and ethical behaviour into the requirements, and most commentary has treated it as a boardroom topic. The licensed text says otherwise. Clause 5.1.1 i) makes promoting quality culture and ethical behaviour a top-management duty, but Clause 5.1.1 h) also requires top management to support other relevant roles to demonstrate leadership in their own areas, and Clause 7.3 e) requires every person doing work under the organization's control to be aware of the organization's quality culture and ethical behaviour.
“Quality culture and ethical behavior is not only a leadership issue. It's every department's issue.”
— Diana Lynn, President and Principal ISO Consultant, MSI
That distinction changes the risk picture. A registrar may sample any department at any site and ask how quality culture and ethical behaviour show up in the work. If the only evidence is a line in management review minutes, sampled sites have little to show. ISO 9001:2026 Annex A.5.1, which is informative and adds no requirement, puts the reason well: ethical behaviour in decisions, actions and interactions can affect all aspects of quality. ISO 14001:2026 does not use either term in its requirements, so this factor applies to the quality side of the ISO transition risk assessment.
For an ISO transition risk assessment, department-level evidence is usually already there; it simply has not been connected. Examples that work in practice:
- Operations: stop-the-line authority used and recorded, and nonconforming output reported rather than reworked quietly.
- Purchasing: supplier selection criteria that include ethical conduct, an approach MSI describes in its article on the ISO 9001 ethical supply chain.
- Sales and customer service: commitments made only within verified capability, and complaints logged honestly.
- Human resources: awareness training records that cover culture and ethics alongside the quality policy and objectives.
- Maintenance and EHS: calibration and inspection results reported as found, not as hoped.
For awareness sessions, MSI's reference list of 200 negative ethics actions gives each department concrete examples to discuss, and the ISO 9001:2026 executive briefing covers the leadership side. In a multi-site network, score this factor per site, because culture is local even when procedures are shared.
Direct Answer: Quality culture and ethical behaviour belong in an ISO transition risk assessment as a department-level factor, because ISO 9001:2026 Clause 7.3 e) requires awareness from every person doing work under the organization's control, and sampled departments at sampled sites must be able to show it.
Section 8 · The Original Asset
What Is the MSI Transition Risk Scorecard?
Measure. Decide. Act.
The MSI Transition Risk Scorecard is a ten-factor tool for running an ISO transition risk assessment in a single working session. It is available free online at the ISO Transition Risk Scorecard page, where each certificate is scored automatically, and as a Word scorecard for recording the result. Score each factor from 1 (low risk) to 3 (high risk) for each certificate. Factor 9 differs by standard: 9a applies to ISO 9001 and 9b to ISO 14001, so each certificate is still scored on ten factors.
In a multi-site organization, score the site-level factors (6, 7 and 9) for the central function and for each site, then carry the highest site score into the total. Factors such as number of sites and site similarity describe the whole network, so they are scored once.
| # | Factor | 1 · Low risk | 2 · Moderate | 3 · High risk |
|---|---|---|---|---|
| 1 | Cycle position | Recertification falls inside the window, 12+ months before the deadline | Only surveillance audits fall inside the window | Next scheduled audit is within 6 months or after the deadline |
| 2 | Number of sites | Single site | 2–9 sites | 10+ sites, or sites across countries |
| 3 | Site similarity | All sites eligible for sampling | Mixed sampled and non-sampled sites | Sites perform significantly different activities |
| 4 | Number of registrars | One registrar for all certificates | Two registrars | Three or more, or one recently acquired site with its own registrar |
| 5 | Registrar readiness | Written transition arrangement and accreditation date confirmed | Arrangement promised but not in writing | No arrangement, or registrar not transitioning |
| 6 | Degree of system change | Procedures already updated to 2026 editions | Updates drafted, not deployed | No updates started |
| 7 | Internal audit readiness | 2026-edition audit objectives defined; auditors trained | Program updated, auditors not yet trained | Program still to the 2015 editions |
| 8 | Management review readiness | 2026 inputs and outputs in the agenda and minutes | Partially updated | Agenda unchanged since 2015 |
| 9a | Culture and ethics evidence (ISO 9001 only) | Awareness records and department examples at every site | Leadership-level evidence plus some departments | Management review minutes only |
| 9b | Context, aspects and compliance obligations (ISO 14001 only) | Reviewed and updated for the 2026 edition at every site | Partially reviewed | Not yet reviewed |
| 10 | Resources and competence | Named owner, budget and time approved at management review | Owner named, resources informal | No owner or approved resources |
| Total score | Risk band | MSI recommended route | Recommended start |
|---|---|---|---|
| 10–15 | Low | Fold the transition into the next scheduled surveillance or recertification audit | At least 9 months before that audit |
| 16–23 | Moderate | Transition ISO 14001 first; consider a special transition audit if no scheduled audit fits; align registrars | At least 12 months before the chosen audit |
| 24–30 | High | Book a planning session, sequence sites by score, resolve registrar status before booking audits | Now |
The bands are deliberately conservative, because starting a few months early costs little, while starting late compresses the evidence-building into the final year. Score honestly; rounding a score down only moves the work later. Record the completed scorecard as documented information under ISO 14001:2026 Clause 6.1.4 and present it at management review, where Clause 9.3.3 decisions on changes and resources make it an approved plan rather than a worksheet.
Section 9 · The Method
How Do You Perform an ISO transition risk assessment Step by Step?
Inventory. Score. Schedule.
Performing an ISO transition risk assessment takes one preparation session and one decision meeting. The sequence below is the order MSI recommends for dual-certified organizations.
- Inventory every certificate. List standard, registrar, accreditation body, scope, sites, issue and expiry dates, and every scheduled audit through September 2029. Verify each entry in CertSearch.
- Map the two clocks. Place each certificate against the Global ACI milestones for its standard, and mark the last scheduled audit before each deadline.
- Request registrar arrangements in writing. Ask each registrar for its accreditation transition date, its approach to transition audit time and whether it will combine ISO 9001 and ISO 14001 transitions in one visit.
- Score the ten factors. Use the MSI Transition Risk Scorecard, online or in Word, as the core of the ISO transition risk assessment for each certificate, scoring the site-level factors for the central function and each site.
- Choose a route and a start date. Apply the decision rules, then work backward from the chosen audit through one internal audit and management review cycle.
- Write it up through your risk procedure. Enter each risk and opportunity the scorecard surfaced into your existing risk register, using the same method and criteria as every other entry. For each factor scored 3, plan the action, the owner, the due date and how effectiveness will be evaluated, as ISO 9001:2026 Clauses 6.1.2 and 6.1.3 and ISO 14001:2026 Clause 6.1.5 require. The ISO transition risk assessment then lives inside the system rather than beside it.
- Plan the changes. Treat the transition as a planned change under Clause 6.3 of each standard, addressing purpose, integrity, resources, responsibilities, communication and how effectiveness will be reviewed.
- Update the audit program. Define 2026-edition audit objectives under Clause 9.2.2 a), use ISO 19011:2026 Clause 5.3 to identify program risks, and make sure every site is covered before the transition audit.
- Approve at management review. Present the scorecard and route; record decisions on changes and resources under Clause 9.3.3; then book the audits.
What records should you keep from an ISO transition risk assessment?
Keep records as you go, not at the end. ISO 14001:2026 Clause 6.1.4 requires the risks and opportunities to be addressed to be available as documented information; ISO 9001:2026 does not explicitly require the risk assessment itself to be documented, but a registrar transitions a certificate on evidence, and these records are that evidence.
| Record | Source | Status |
|---|---|---|
| Completed scorecard and the risk and opportunity entries it produced | ISO 14001:2026 Clause 6.1.4 | Requirement (ISO 14001); MSI recommendation (ISO 9001) |
| Action plan with owners, due dates and how effectiveness will be evaluated | ISO 9001:2026 Clauses 6.1.2 b) and 6.1.3 b); ISO 14001:2026 Clause 6.1.5 | Planning is a requirement; keeping it in writing is an MSI recommendation |
| Change plan covering purpose, integrity, resources, responsibilities, communication and review | Clause 6.3 of each standard | Planning is a requirement; keeping it in writing is an MSI recommendation |
| Registrar written transition arrangements and CertSearch verification of each certificate | Global ACI transition requirements | MSI recommendation |
| Audit program and audit results covering every site | Clause 9.2.2 of each standard | Requirement (documented information) |
| Management review results, including decisions on changes and resources | Clause 9.3.3 of each standard | Requirement (documented information) |
| Follow-up review of whether the actions worked | ISO 9001:2026 Clause 9.3.2 g); ISO 14001:2026 Clause 9.3.2 b) 4) | Requirement as a management review input |
Steps 6 through 8 are where most of the effort sits. If your current risk procedure was written for one standard, the IMS Risk Management Procedure Template gives one procedure for risks, aspects and hazards across an integrated system, so the transition entries sit in the same register as everything else, and the ISO 14001:2026 Transition course walks every environmental change clause by clause. For auditors, MSI's ISO 14001:2026 Internal Auditing course is available now, and the updated ISO 9001:2026 and 13485 Internal Auditor Training and ISO Internal Auditor Online Workshop are coming soon with 2026 content.
Section 10 · In Practice
What Does an ISO transition risk assessment Look Like in Practice?
Plan. Practice. Prove.
The two scenarios below are illustrative, not client case studies. Consider a manufacturing network with six plants, a central engineering office and two registrars: one holds the multi-site ISO 9001 certificate, and a second holds an ISO 14001 certificate for three plants acquired two years ago. Its ISO transition risk assessment would score the ISO 14001 certificate at 25 if its next scheduled audit falls after October 31, 2027, its registrar has not issued a written arrangement, and the acquired plants still run their own procedures. The ISO 9001 certificate might score 17.
The decision follows directly from those scores. The team would transition ISO 14001 first, deploy one procedure set to all six plants, confirm the second registrar's arrangement before booking, and schedule the ISO 9001 transition at the following recertification. Leadership could also evaluate consolidating both certificates with one registrar at that recertification, recording the decision as an opportunity under Clause 6.1.3.
Now consider a technology company with three similar offices and one registrar, scoring 13 on both certificates. Its route is simpler: fold both transitions into a combined surveillance audit roughly a year out, with one integrated internal audit and one management review in between. The difference between the two organizations is not the standards; it is sites and registrars, which is exactly what an ISO transition risk assessment is built to expose.
Section 11 · Authority
How Does ISO Consulting Support an ISO transition risk assessment?
Experience. Evidence. Results.
An ISO transition risk assessment is only as good as the judgment behind each score, and that judgment comes from having seen transitions before. Management Systems International (MSI) brings 28 years of experience to that work, a span that includes the 2000, 2008 and 2015 ISO 9001 revisions and the 2004 and 2015 ISO 14001 revisions. MSI's track record includes 80+ certifications supported, 200+ audits attended and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare and other regulated industries.
Those numbers matter for one practical reason: 200+ audits attended means MSI has watched how registrars sample sites, calculate transition time and close out multi-site findings, from the client's side of the table. Good ISO consulting turns that experience into a plan your team owns, while the registrar stays independent. For organizations that want the transition handled end to end, SurePath delivers certification to the 2026 editions, and SureResults keeps an existing system current through the transition and beyond.
If you want to measure progress, track four numbers monthly from your ISO transition risk assessment: the total score per certificate, the number of sites with a factor scored 3, the number of registrars with written arrangements, and the number of departments with recorded culture and ethics awareness. Falling scores are the evidence leadership needs that the plan is working.
Section 12 · Next Steps
What Should You Do After Your ISO Transition Risk Assessment?
Document. Deploy. Deliver.
Every factor in the scorecard has a direct next step. Pick the one that matches your highest score.
Update Every Procedure Once — Not Once Per Site
Scored high on system change or site similarity? MSI's ISO Procedure Templates and Guides are editable Word procedures written to the 2026 editions, with clause cross-references and the judgment calls already made. Deploy one set from the central function to every site, and your transition becomes an edit instead of a rewrite.
Score Your Transition in Five Minutes, Free
Not sure where to start? Answer 10 questions, or 14 for an integrated Q/EMS, and see each certificate's score, risk band, recommended audit route and highest-risk factor the moment you finish. No sign-in needed to see your result.
Move Your ISO 14001:2015 System to 2026 in a Week
ISO 14001 sets the earlier deadline. The ISO 14001:2026 Procedure Templates and Guides package was built to help experienced EHS managers update their current ISO 14001:2015 system to the 2026 edition in a week's time, with the complete procedure set and the ISO 14001:2026 Transition course included.
Let Management Review Approve the Transition Plan
Clause 9.3.3 in both standards is where top management decides on changes and resources. MSI's ISO Management Review Toolkits give you the agenda, input checklist and minutes format to present your scorecard, record the decision, and show every registrar a transition led from the top. Running an integrated system? Go straight to the Q/EMS Management Review Tool Kit for ISO 9001:2026 and ISO 14001:2026.
Score Your Transition With an MSI Expert
Bring your certificate list, sites and audit dates to a planning session. An MSI expert will run the Transition Risk Scorecard with you and leave you with a dated route for each certificate and each registrar. Call 760-434-9141.
Section 13 · FAQ
ISO Transition Risk Assessment: Frequently Asked Questions
Ask. Answer. Act.
What is an ISO transition risk assessment?
An ISO transition risk assessment is a scored review of what could delay moving ISO 9001 and ISO 14001 certificates to their 2026 editions. It rates timing, sites, registrars, readiness and resources, then sets an audit route and start date for each certificate.
When must the ISO 9001:2026 and ISO 14001:2026 transitions be complete?
As of October 1, 2026, Global ACI requires ISO 14001 transitions to be complete by April 30, 2029 and ISO 9001 transitions by September 30, 2029. New certifications are issued only to the 2026 editions from October 31, 2027 for ISO 14001 and March 31, 2028 for ISO 9001.
Can ISO 9001 and ISO 14001 transition at the same audit?
Yes, if the timing works and your registrar is accredited for both 2026 editions by then. Global ACI allows transition at a surveillance audit, a recertification audit or a special transition audit, so a combined visit is possible. An ISO transition risk assessment checks whether one date can meet the earlier ISO 14001 deadline.
How does multi-site sampling affect the transition?
Under IAF MD 1:2023, registrars audit the central function and a partly random sample of sites, so every site must be ready at the same time. An open major nonconformity at any one site holds the certification decision for all listed sites until corrective action is satisfactory.
What happens if our registrar does not transition to the 2026 editions?
For ISO 14001, a registrar that will not transition must notify clients in writing by January 31, 2027. Its accredited certification ends with the transition period, so you would transfer to another accredited registrar under IAF MD 2:2023, which accepts valid, unsuspended certificates after a pre-transfer review.
Is quality culture and ethical behaviour only a top-management requirement?
No. ISO 9001:2026 Clause 5.1.1 i) assigns promotion to top management, but Clause 7.3 e) requires every person doing work under the organization's control to be aware of the organization's quality culture and ethical behaviour, so evidence is needed in every department.
Is there a free tool to run an ISO transition risk assessment?
Yes. MSI's free ISO Transition Risk Scorecard scores each certificate on ten factors in about five minutes and returns a risk band, a recommended audit route and the highest-risk factor, with a combined audit test for integrated Q/EMS systems.
Does ISO require a documented ISO transition risk assessment?
Neither standard names one. ISO 14001:2026 Clause 6.1.4 requires risks and opportunities to be addressed to be available as documented information, and both standards require planned change under Clause 6.3, so a documented ISO transition risk assessment is the simplest way to show both.
Related Reading
Continue the Transition Series
ISO Transition Risk Scorecard (Free Tool)
Score each certificate on ten factors and get your audit route in five minutes.
ISO Transition Planning: Why Next Year Wins It All
The nine-milestone calendar that turns this assessment into dates.
ISO 9001 and 14001 Transition: Why One Plan Wins
How to run both clause updates as one integrated project.
Multi-Site ISO Certification: Why 1 System Always Wins
The central-function architecture behind IAF MD 1 sampling.
ISO Registrar: The Critical Choice Behind Every Certificate
How to evaluate, keep or change a certification body.
References and Primary Sources
- Global ACI — Global ACI Publishes Transition Requirements for ISO 9001:2026 (September 16, 2026)
- Global ACI-TECH-3-TR 2029-09-30 (M), Transition Requirements for ISO 9001:2026
- Global ACI — Global ACI Publishes Transition Requirements for ISO 14001:2026 (September 14, 2026)
- Global ACI-TECH-3-TR 2029-04-30 (M), Transition Requirements for ISO 14001:2026
- Global ACI — About Global ACI
- Global ACI — About the Global ACI MRA
- IAF MD 1:2023, Audit and Certification of a Management System Operated by a Multi-Site Organization
- IAF MD 2:2023, Transfer of Accredited Certification of Management Systems
- IAF ID 14:2023, Guidance on Audit Time for Integrated Audit of Multi-Site Management Systems
- IAF document register (MD 1, MD 2, MD 11)
- ANAB — ISO/IEC 17021-1 Management Systems Documents
- CertSearch — Global database of accredited certifications
- ISO — ISO 9001 Quality management
- ISO — ISO 14001 Environmental management
- ISO — ISO 31000 Risk management
- ISO — ISO/IEC 17021-1 Requirements for bodies providing audit and certification of management systems
Clause references verified against the licensed texts of ISO 9001:2026, ISO 14001:2026 and ISO 19011:2026. Transition dates as of October 1, 2026; confirm your registrar's written arrangement before booking audits.
About Management Systems International (MSI)
Diana Lynn, President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.
Veteran-owned and female-owned · msi-international.com · 760-434-9141


