MSI site analytics pixel

QMS Compliance vs Certification: The Essential Truth for ISO 9001, 13485, 14001, 45001 and 7101

ISO Compliance · All Five Standards

By Diana Lynn, President and Principal ISO Consultant, MSI · Updated October 4, 2026

QMS compliance is a management system meeting its own requirements and its ISO standard every day, proven by current records rather than a certificate. A certificate is a photograph taken on audit day. QMS compliance is the live feed, and in MSI’s experience most organizations never check whether the camera is still recording.

That gap is why so many people search for the meaning of QMS compliance. They hear “compliant” and “certified” used as if they were the same word. Many also believe that following their procedures makes them compliant. It does not, unless the system is also auditing itself. The internal audit is one of the requirements, and it is the one companies most often miss without realizing it.

They are not. One is a condition you either sustain or lose between visits. The other is an accredited third party’s written opinion about that condition on specific dates.

This guide explains the difference across all five standards MSI implements: ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101. It also gives you a scorecard to test your own system in fifteen minutes. We use “QMS compliance” because it is the phrase most people search, but the same test applies to environmental, safety and healthcare management systems.

Direct Answer

QMS compliance means your management system conforms to its own documented requirements and to the ISO standard right now, with records to prove it. Certification is an accredited body confirming that at audit time. Registrars expect every requirement audited internally each year, so without annual internal audits you are not compliant, certified or not.

Key Takeaways

  • QMS compliance is a continuous state; ISO certification is a periodic, independent verification of that state.
  • ISO 9001:2026 Clause 3.15 defines conformity as the fulfilment of a requirement, and notes that “conformance” is a deprecated synonym.
  • ISO 9001, 13485, 14001, 45001 and 7101 all require internal audits at planned intervals and a management review by top management.
  • Accredited certification bodies must audit every certified client at least once each calendar year, and each surveillance visit reviews internal audits and management review.
  • Registrars expect every requirement of the standard to be internally audited each year; an organization that skips internal audits is not compliant, even if its procedures are followed and its certificate is current.

Definitions

What Does QMS Compliance Mean?

Define. Prove. Sustain.

QMS compliance means three things are true at the same time. Your system meets the requirements of the standard. It meets the requirements you wrote for yourself in procedures, policies and objectives. And it is effectively implemented and maintained, not only documented. Those three tests come straight from the purpose of internal audit in ISO 9001:2026 Clause 9.2.1, which asks whether the system conforms to the organization’s own requirements and the standard’s requirements, and whether it is effectively implemented and maintained.

Notice what ISO itself calls this. The standards use “conformity,” not “compliance,” when they talk about meeting their own requirements. ISO 9001:2026 defines conformity as fulfilment of a requirement and labels “conformance” a deprecated term.

ISO reserves “compliance” for something narrower. In ISO 14001:2026 Clause 3.2.9, compliance obligations are legal requirements an organization has to comply with and other requirements it has to or chooses to comply with. ISO 45001 uses the parallel idea of legal requirements and other requirements.

So when a quality manager says “QMS compliance,” the precise meaning is conformity of the management system, plus fulfilment of any legal, regulatory, customer or voluntary obligations the system has taken on. Most people use the everyday word, and that is fine. What matters is that both halves need evidence. MSI’s guide to evaluation of compliance under ISO 14001, ISO 45001 and ISO 7101 covers the legal-obligation half in depth. This article focuses on the management-system half, which lives or dies on internal audit.

TermWhere ISO defines or uses itWhat it means in practice
ConformityISO 9001:2026 Clause 3.15Fulfilment of a requirement of the standard or of your own system
NonconformityISO 9001:2026 Clause 3.16Non-fulfilment of a requirement, including your own scheduled audits
Compliance obligationsISO 14001:2026 Clause 3.2.9Legal requirements and other requirements you must or choose to meet
Legal and other requirementsISO 45001:2018 Clause 6.1.3OH&S obligations the system must determine, access and evaluate
Applicable regulatory requirementsISO 13485:2016 Clause 8.2.4Regulatory criteria an internal audit must cover in a device QMS
CertificationISO Certification guidanceWritten assurance from an independent body that a system meets requirements

Compliance vs Certification

QMS Compliance vs Certification: What Is the Difference?

Condition. Confirmation. Credibility.

Direct Answer

QMS compliance is the condition; certification is the confirmation. Compliance is owned by you and must be true every day. Certification is a decision by an accredited body, based on sampled evidence from audits held at least once a calendar year. You can be compliant without a certificate, and certified while quietly drifting out of compliance.

ISO is direct about its own role. On its certification guidance page , ISO explains that it writes standards but does not perform certification or issue certificates. Independent certification bodies do that work. ISO’s overview of management system standards adds that certification is not a requirement, and organizations can benefit from implementing a standard without being certified.

That means certification is optional, but QMS compliance is not optional for anyone who claims to follow a standard. The moment you tell a customer you “follow ISO 9001” or are “ISO compliant,” you have made a claim about conformity.

The only thing that changes with certification is who has checked the claim. MSI tells the story of a firm that lost a bid to an uncertified competitor claiming to be “ISO compliant” in its article on ISO for engineering firms. An unverified compliance claim costs nothing to print. An earned one has records behind it.

QuestionQMS complianceISO certification
Who decides?Your organization, through internal audit and management reviewAn accredited certification body
How often is it tested?At the planned intervals you set, and every working day in practiceAt least once per calendar year, with recertification every three years
What evidence counts?Audit reports, corrective actions, management review minutes, monitoring recordsA sample of that same evidence, reviewed by an external auditor
Is it required?Yes, if you claim to follow the standardVoluntary, unless a customer, contract or regulator requires it
Can it be verified by outsiders?Only if they ask to see your recordsYes, through the certification body and accredited certificate databases
What makes it lapse?Skipped audits, unclosed actions, missed reviews, unmanaged changeSuspension or withdrawal by the certification body

Accredited certificates can be checked. ISO’s help center explains how to verify an accredited certification through the certification body or the global certificate database, and the ISO Survey now draws on that same accredited data. MSI explains how that accreditation chain works in its guide to what ISO is and who grants certification and its guide to choosing an ISO registrar. A certificate tells a buyer that someone independent looked. It cannot tell anyone what happened in your system last Tuesday.

“If you are not doing internal audits on an annual basis, you are not compliant.”

— Diana Lynn, President and Principal ISO Consultant, Management Systems International (MSI)


The Internal Audit Test

Why Does QMS Compliance Depend on Annual Internal Audits?

Plan. Audit. Prove.

Direct Answer

QMS compliance depends on internal audits because the internal audit is itself a requirement, not an optional check. Registrars expect every requirement of the standard to be internally audited each year, management review needs the results, and certification bodies review your internal audits every calendar year. No annual internal audit means no compliance.

Here is the blind spot MSI sees most often. A company follows its procedures, ships good product, and passes its last external audit, so it assumes it is compliant. But it has not internally audited its own system in a year or more. That company is not compliant, because internal audit is one of the requirements it agreed to meet.

Across the certification industry, registrars expect every requirement of the standard to be internally audited each year. The standards express the frequency as “planned intervals,” and registrars expect that plan to cover the whole standard every twelve months. In 28 years of implementation and 200+ audits attended, MSI has seen that expectation applied consistently. Three requirements explain why it holds.

1. Your audit program turns your schedule into a requirement

ISO 9001:2026 Clause 9.2.2 requires the organization to plan, establish, implement and maintain an audit program, “including the frequency.” Once you set that frequency, it is one of your own requirements under Clause 9.2.1 a) 1). Missing it is a nonconformity against your own system. The same structure appears in ISO 14001:2026, ISO 45001:2018 and ISO 7101:2023. ISO 13485:2016 Clause 8.2.4 goes further and requires a documented procedure for planning and conducting audits.

2. Management review cannot happen properly without audit results

ISO 9001:2026 Clause 9.3.2 d) 3) lists audit results as a required management review input, and the review itself must happen at planned intervals. If no audit has happened since the last review, that input is empty. A management review with an empty audit input is not a complete review, which means two clauses fail together. MSI’s ISO Management Review Toolkits build that audit-results input into the agenda so the gap is visible before the meeting, not after it.

3. Certification bodies must look at your internal audits every year

Certification bodies operate under ISO/IEC 17021-1. Its surveillance rule requires an audit at least once each calendar year, except in recertification years, as the European co-operation for Accreditation explains in its FAQ on Clause 9.1.3. The accreditation body IAS summarizes the related rule in its ISO/IEC 17021-1 Section 9 overview: each surveillance includes a review of internal audits and management review, and Stage 1 checks whether they are being planned and performed. A year without an internal audit leaves the external auditor nothing to review.

Informative Annex A.9.2 of ISO 9001:2026 adds context, though not a new duty. It explains that internal audit applies to all processes within the QMS, and that audit frequency and scope are influenced by risks and by changes in internal and external issues. Read together, those points describe an audit program that touches every process within a cycle you can defend. Registrars expect that cycle to be twelve months, with every requirement covered. MSI’s guide to internal audit planning under ISO 19011:2026 shows how to build it, and its internal audit risk matrix shows how to weight high-risk processes without leaving others unaudited.

Internal Audit Services · On-Site or Online

We Run Your Internal Audits. Every Requirement, Every Year.

MSI’s independent auditors audit your ISO 9001, 13485, 14001, 45001 or 7101 system against every requirement, on-site or online, and write findings your team can act on. Your twelve-month cycle stays complete, your management review gets real audit results, and your registrar finds a full audit record waiting.

Have MSI Perform Your Internal Audits →


Five Standards, One Principle

How Does QMS Compliance Work Across ISO 9001, 13485, 14001, 45001 and 7101?

Same Structure. Different Stakes.

Every standard MSI implements shares the same backbone for QMS compliance: internal audit at planned intervals, a management review by top management, and corrective action when something fails. The differences sit in what each audit must cover and who else can ask to see the results. The table below is current as of October 4, 2026.

Standard (current edition)Internal audit clauseManagement review clauseWhat raises the stakes
ISO 9001:2026 (published Sept 16, 2026)9.29.3Objectives, criteria and scope defined for each audit; eight review inputs at 9.3.2
ISO 13485:20168.2.45.6Audits cover applicable regulatory requirements; documented procedure required; FDA can inspect audit records under the QMSR
ISO 14001:2026 (published Apr 15, 2026)9.29.3The audit program itself must be available as documented information; evaluation of compliance at 9.1.2
ISO 45001:2018 (with Amd 1:2024)9.29.3Relevant audit results reported to workers and their representatives; evaluation of compliance at 9.1.2
ISO 7101:20239.29.3Audits reach clinical and non-clinical processes alike; service user safety rides on the result

ISO 9001:2026: per-audit objectives make thin audits visible

ISO 9001:2026 was published on September 16, 2026. Clause 9.2.2 a) requires audit objectives, criteria and scope for each audit, and Clause 9.2.2 d) requires appropriate correction and corrective actions without undue delay. Audits that only confirm a procedure exists will struggle to show a stated objective was met. MSI walks through the full list of revisions in ISO 9001:2026 changes and the most common failure points in internal audit mistakes even seasoned auditors make. For quality teams, the ISO 9001 Procedure Templates and Guides bundle is the fastest way to put a defensible internal audit procedure in place.

ISO 13485: QMS compliance is literally regulatory

In a medical device QMS, Clause 8.2.4 of ISO 13485:2016 requires internal audits to check conformity with planned arrangements, the standard, the organization’s own QMS requirements and applicable regulatory requirements. That last item turns QMS compliance into regulatory compliance. In the United States, the FDA’s Quality Management System Regulation took effect on February 2, 2026 and incorporates ISO 13485 by reference. The FDA’s QMSR frequently asked questions state that the agency now has authority to inspect management review, quality audit and supplier audit reports. MSI covers what that means for device teams in its article on medical device cybersecurity as a QMS issue, and the role that holds it together in the ISO management representative.

ISO 14001:2026: the audit program must be on paper

ISO 14001:2026 was published April 15, 2026, and certified organizations have until April 30, 2029 to transition, as of October 4, 2026. Its Clause 9.2.2 lists the audit program itself among the documented information that must be available, alongside evidence of implementation and results. Clause 9.1.2 separately requires the organization to determine how often compliance obligations are evaluated and to maintain knowledge of its compliance status. An EMS can therefore lapse on two clocks at once. MSI explains how to run both on one plan in the combined ISO 9001 and 14001 transition.

For Experienced EHS Managers

Update Your ISO 14001:2015 System to 2026 in a Week

The ISO 14001:2026 Procedure Templates and Guides were built for experienced EHS managers who already run an ISO 14001:2015 system and need it updated to the 2026 edition in a week’s time. The internal audit procedure carries the documented audit program requirement and per-audit objectives already written in.

See the ISO 14001:2026 Bundle →

ISO 45001: workers see the results

ISO 45001:2018, with Amendment 1:2024, remains the current edition as of October 4, 2026, with a revision underway at ISO. Its Clause 9.2.2 goes beyond reporting to managers. Relevant audit results must also reach workers and, where they exist, workers’ representatives.

That makes a skipped audit visible on the shop floor, not just in the quality office. Combined with legal requirements at Clause 6.1.3 and evaluation of compliance at Clause 9.1.2, an OH&S system carries some of the heaviest evidence load of the five. MSI’s ISO 45001 consulting page shows how the safety layer is built around real hazards.

ISO 7101: healthcare quality needs audit evidence most of all

ISO 7101:2023 is the first international standard for healthcare quality management. It follows the harmonized structure, with internal audit at Clause 9.2 and management review at Clause 9.3.

Healthcare organizations often already live with accreditation surveys, which can make QMS compliance feel redundant. It is not. An internal audit under ISO 7101 tests whether the management system works across scheduling, credentialing, facilities and service user feedback, not only at the bedside. MSI’s ISO 7101 healthcare quality consulting and its analysis of management system oversight explain why that reach matters. The ISO 7101:2023 Procedure Templates and Guides give healthcare teams the internal audit procedure in working form.

Running more than one of these standards? MSI’s editable IMS Internal Audit Procedure Template and Guide covers ISO 9001, ISO 14001:2026 and ISO 45001 in one controlled document, so a single audit program can demonstrate QMS compliance for all three. MSI’s connected quality management model applies the same idea across multiple sites.


Requirement Status

Which QMS Compliance Items Are Requirements and Which Are Recommendations?

Shall. Should. Smart.

A requirement uses “shall.” A NOTE is for consideration only. Annex A is informative and adds no requirements. Rules written for certification bodies bind them, not you. Mixing these up is the fastest way to over-build or under-build a system, so the table labels each item.

ItemSourceStatus
Conduct internal audits at planned intervalsISO 9001:2026, 14001:2026, 45001:2018, 7101:2023 Clause 9.2.1; ISO 13485:2016 Clause 8.2.4Requirement
Maintain an audit program including frequency, methods, responsibilities, planning and reportingClause 9.2.2 in the harmonized standardsRequirement
Define objectives, criteria and scope for each auditISO 9001:2026 and ISO 14001:2026 Clause 9.2.2 a)Requirement
Audit program available as documented informationISO 14001:2026 Clause 9.2.2Requirement
Documented procedure for internal auditISO 13485:2016 Clause 8.2.4Requirement
Audit results as a management review inputISO 9001:2026 Clause 9.3.2 d) 3) and equivalentsRequirement
Internal audit applies to all processes; frequency influenced by risk and changeISO 9001:2026 Annex A.9.2Informative Annex A (no added requirement)
Internal audits can form the basis for a declaration of conformityISO 9001:2026 Clause 3.18, Note 5 to entryNOTE (consideration only)
Audit program schedule, number, duration and frequencyISO 19011:2026 Clause 5.1Guidance (“should”)
Surveillance audit at least once per calendar year, reviewing internal audits and management reviewISO/IEC 17021-1Requirement on certification bodies, not on your organization
Internally audit every requirement and process at least every 12 monthsRegistrar expectation across the certification industryIndustry expectation; MSI practice

Original MSI Asset

How Can You Score Your QMS Compliance in 15 Minutes?

Score. Decide. Act.

MSI created the 12-Month QMS Compliance Evidence Scorecard for this article. It turns the requirements above into ten yes-or-no evidence checks you can run with your records open. Score each item 2 if the evidence exists for the last twelve months, 1 if it exists but is incomplete or late, and 0 if it does not exist. It works for ISO 9001, 13485, 14001, 45001 and 7101 systems alike.

#Evidence check (last 12 months)Clause basisScore 0 to 2
1Every requirement and process in scope was internally audited9.2.1; Annex A.9.2; registrar expectation 
2Each audit had written objectives, criteria and scope9.2.2 a) 
3No auditor audited their own work9.2.2 b) 
4Results reached relevant managers (and workers, for ISO 45001)9.2.2 c) 
5Findings were corrected and corrective actions closed without undue delay9.2.2 d); 10.2 
6Audit results were presented at a management review9.3.2 
7Management review produced recorded decisions on improvement, changes and resources9.3.3 
8Legal, regulatory and other obligations were evaluated at your set frequency14001 and 45001 9.1.2; 13485 8.2.4 
9Audit program, implementation evidence and results are retained9.2.2 
10The audit program was re-planned after changes or poor audit results9.2.2 

Decision rules. A total of 18 to 20 means QMS compliance is current and demonstrable. A total of 13 to 17 means the system is compliant on paper but drifting, and the weakest items need owners and dates. A total of 12 or below means the system is not compliant today. One override applies to every total: a 0 on item 1 or item 6 means you are not compliant, because the audit and review chain is broken.

Scorecard Showed Gaps? · Most Popular

Your Internal Audit Procedure, Already Written

MSI’s ISO Procedure Templates and Guides are finished, editable Word procedures for ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101, annotated from 200+ audits attended. The internal audit procedure, audit schedule and corrective action forms are built to interlock, so QMS compliance has a paper trail from the first audit.

Browse the Procedure Templates →

If the scorecard exposes a transition problem as well, pair it with MSI’s free interactive ISO Transition Risk Scorecard for ISO 9001:2026 and ISO 14001:2026.


Drift Between Audits

What Happens When QMS Compliance Lapses Between Certification Audits?

Drift. Detect. Decide.

Systems rarely fail in one dramatic moment. MSI client experience suggests they erode in a predictable order. First the internal audit slips “just one quarter” because of a busy season.

Then the management review is held without audit results, so leadership approves a status that nobody verified. Then corrective actions age because no one is asking about them. By the time the external auditor arrives, procedures still describe a system that people stopped following months earlier.

The cost is not a failed visit. It is the operating problem that the audit would have caught: a supplier whose performance nobody reviewed, a training record that expired, a calibration that lapsed, a legal requirement that changed. Procedures that work in practice catch those problems in-house. Procedures that fail in practice let them reach customers, workers, patients or the environment. MSI makes the same point in its article on the ISO audit as a recurring test of trust, where certification is something you keep earning, cycle after cycle.

“Having systems, acting on what the records are reporting, and never letting anyone deny the facts is what prevents good systems from deteriorating.”

— Diana Lynn, President and Principal ISO Consultant, MSI

Integrity is the thread that runs through all of it. A certificate records a promise, and QMS compliance is how that promise is kept between visits, when no external party is watching. MSI develops that idea in ISO standards and integrity.


Recovery

How Do You Restore QMS Compliance After Missed Internal Audits?

Restart. Review. Recover.

Direct Answer

Restore QMS compliance by holding an “End in Mind” management review using the data you already have, marking missing data TBD with dates, then running a risk-weighted internal audit of every process, closing findings, and feeding results into the next review. Most organizations can rebuild a defensible evidence chain in one cycle.

MSI recommends starting with management review rather than the audit, because review is where leadership commits resources. In an “End in Mind” review, you put every required input on the slides, fill in the data you already hold, and mark missing items TBD with a date and an owner. The gaps become a visible action plan approved by top management, instead of a list the quality manager carries alone. MSI’s management review toolkits are built for exactly that first meeting.

  1. Hold the “End in Mind” management review. Present every required input, record decisions and resources, and date every TBD.
  2. Re-plan the audit program by risk. Put the highest-risk and longest-unaudited processes first, with written objectives for each audit.
  3. Assign impartial auditors. Use trained staff from other departments, or an independent internal auditor if your team is too small to stay objective.
  4. Audit every process within the cycle. Record findings against the clause and your own procedure.
  5. Close the findings. Correct, find root causes, and verify that corrective actions worked.
  6. Close the loop at the next review. Present audit results, action status and decisions, and set the next twelve-month cycle.

For teams that would rather not rebuild audit capability in-house, MSI performs independent internal audits against all five standards, on-site or remotely. MSI’s SureResults ISO maintenance program keeps the twelve-month clock from lapsing by running the audits, supporting management review and preparing registrar visits year-round. Teams building their own auditors can develop the method through MSI’s internal audit skills guidance. MSI’s updated internal auditor courses for the 2026 editions are coming soon, starting with the ISO Internal Auditor Online Workshop.


ISO 9001:2026 Timing

How Does the ISO 9001:2026 Transition Affect QMS Compliance?

Publish. Plan. Transition.

As of October 4, 2026, ISO 9001:2026 is published and ISO 9001:2015 certificates remain valid during the transition. Global ACI, which replaced the IAF and ILAC on January 1, 2026, has set the rules in its transition requirements for ISO 9001:2026. From March 31, 2028, new and initial accredited certifications may only be issued to the 2026 edition. Organizations certified to the 2015 edition have until September 30, 2029 to complete their transition.

For QMS compliance, the practical point is evidence lead time. A transition audit will look for at least one internal audit with per-audit objectives and one management review that carries the 2026 inputs. Neither can be produced the week before the visit. MSI’s guide to ISO transition planning works backward from your next surveillance date, and its ISO 9001:2026 consultant test helps you decide whether outside ISO consulting support is worth it. The ISO 9001 Auditing Practices Group, convened by ISO’s quality committee and the accreditation community, also publishes free guidance papers on internal audit.


Why MSI

Why Does Measurable ISO Consulting Experience Matter for QMS Compliance?

Experience. Evidence. Endurance.

QMS compliance is a judgment about evidence, and judgment improves with exposure. Management Systems International (MSI) has 28 years of ISO consulting behind that judgment, with 80+ certifications supported, 200+ audits attended and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare and other regulated industries. MSI is veteran-owned and female-owned, and it attends certification audits alongside its clients rather than handing over documents and leaving.

That experience is why MSI’s ISO consulting work starts with how your people actually work, then writes procedures that match. A procedure that matches real work is one people follow, and a followed procedure is the cheapest form of QMS compliance there is. For organizations building a system from the beginning, MSI’s SurePath turnkey certification program builds the internal audit program from day one. You can learn more about MSI’s approach on the ISO consulting page, or watch the free ISO Executive Decision Briefs for a leadership-level view of what each standard asks of top management.


Next Steps

What Is the Fastest Path to Demonstrable QMS Compliance?

Choose. Click. Comply.

If you scored below 18, start with option 1. Pick the option that matches where your scorecard landed. Each one leads directly to the resource or conversation that closes that gap.

1 · Audits have lapsed or never started

Let MSI Perform Your Internal Audits, On-Site or Online

Independent, objective-led internal audits covering every requirement of ISO 9001, 13485, 14001, 45001 or 7101. Choose a one-time audit to restore QMS compliance now, or SureResults to keep the twelve-month cycle on schedule year after year.

Book your internal audit →  ·  See how SureResults works →

2 · Need the documents

Stop Writing Procedures From Scratch

Finished, editable procedures for all five standards, with the internal audit, corrective action and management review procedures already linked so the evidence chain holds together.

Get the ISO Procedure Templates and Guides →

3 · Quality system on ISO 9001

The Complete ISO 9001 Procedure Set

Every ISO 9001 procedure in working form, including an internal audit procedure that schedules every process and records objectives for each audit.

See the ISO 9001 bundle →

4 · Environmental system on ISO 14001

Move Your ISO 14001:2015 EMS to 2026 in a Week

Built for experienced EHS managers updating an existing ISO 14001:2015 system to the 2026 edition in a week’s time, with the documented audit program, per-audit objectives and evaluation of compliance already written in.

See the ISO 14001:2026 bundle →

5 · Management review is overdue

Run a Decision-Ready Management Review This Month

Clause-by-clause presentation decks and minutes forms for ISO 9001:2026, 13485, 14001:2026, 45001 and 7101, so audit results and every other required input reach leadership with an owner attached.

Explore the ISO Management Review Toolkits →

6 · Not sure where you stand

Book a 30-Minute Planning Session

Bring your scorecard total. An MSI consultant will tell you which items to fix first and what a realistic recovery timeline looks like. Call 760-434-9141.


FAQ

QMS Compliance: Frequently Asked Questions

Ask. Answer. Act.

What does QMS compliance mean?

QMS compliance means a management system meets its own documented requirements and the requirements of its ISO standard, and is effectively implemented and maintained, with current records to prove it. ISO's precise word for this is conformity, defined in ISO 9001:2026 Clause 3.15 as fulfilment of a requirement.

Is QMS compliance the same as ISO certification?

No. QMS compliance is a condition your organization must sustain every day. ISO certification is an accredited certification body's written confirmation of that condition, based on audits held at least once per calendar year. You can be compliant without being certified, and certified while drifting out of compliance between visits.

Can a company be ISO compliant without being certified?

Yes. ISO states that certification to its management system standards is not a requirement. A company can achieve QMS compliance without a certificate, but the claim is unverified unless it can show internal audit reports, management review records and closed corrective actions on request.

How often must internal audits be done for QMS compliance?

At least annually, covering every requirement. Registrars across the certification industry expect each requirement of the standard to be internally audited every year, and they review internal audits at every surveillance visit. A company that follows its procedures but skips internal audits does not have QMS compliance.

Does an ISO certificate prove QMS compliance today?

Not by itself. A certificate shows that an accredited body found the system conforming on the dates it audited. QMS compliance today is shown only by current evidence: recent internal audits, a management review within its planned interval, and corrective actions closed without undue delay.

Do ISO 13485, 14001, 45001 and 7101 have the same internal audit requirement as ISO 9001?

All five require internal audits at planned intervals, so QMS compliance rests on the same principle. The details differ: ISO 13485 Clause 8.2.4 adds applicable regulatory requirements and a documented procedure, ISO 14001:2026 requires the audit program to be documented, and ISO 45001 requires relevant results to reach workers.

How quickly can QMS compliance be restored after missed internal audits?

Most organizations can rebuild a defensible QMS compliance evidence chain within one audit cycle. MSI recommends starting with an End in Mind management review that marks missing data TBD with dates, then auditing every process by risk, closing findings, and presenting the results at the next review.

Does ISO 9001:2026 change QMS compliance requirements?

ISO 9001:2026, published September 16, 2026, keeps internal audit at Clause 9.2 and requires objectives, criteria and scope for each audit. For QMS compliance during transition, plan at least one internal audit and one management review carrying the 2026 inputs before your transition audit; certified organizations have until September 30, 2029.


References and Sources

About Management Systems International (MSI)

Diana Lynn, President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI’s early years, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

Veteran-owned · Female-owned · About MSI · msi-international.com · 760-434-9141

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 15 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply