Skip to main content
Quality Frameworks

Stop Chasing ISO 9001 Certificates: Build a QMS That Actually Works

ISO 9001 is the world's most used QMS, but too many companies treat it as a badge. We argue for a framework that prioritizes prevention and improvement over compliance theater.

The 1.26 Million Problem

As of the end of 2022, there were 1,265,216 valid ISO 9001 certificates worldwide (ISO Survey 2022). That's over a million organizations that have, at least on paper, implemented a quality management system. But if you've worked in this field for any length of time, you know the dirty secret: many of those certificates are nothing more than expensive wallpaper. They hang on the wall, but the processes behind them are ossified, the audits are box-ticking exercises, and the QMS is a binder that nobody opens until the surveillance visit looms.

We need to stop treating ISO 9001 as a certificate to be earned and start treating it as a framework for genuine improvement. The standard itself isn't the problem—it's how we use it.

A Framework, Not a Finish Line

ISO 9001 is built on the Plan-Do-Check-Act (PDCA) cycle and a process approach (ASQ). That's the heart of it: a cycle of planning, doing, checking, and acting that, when repeated, drives continuous improvement. But too many organizations see the certificate as the finish line. They get certified, then the PDCA cycle stops. The improvement culture dies, and the QMS becomes a static document.

We've all seen it. The quality manual that hasn't been updated in years. The internal audit that's scheduled only because it's required. The management review that's a 15-minute slide deck. That's not a QMS; that's a museum piece.

Prevention Over Detection: The Heart of the Matter

The standard's principles are clear: quality assurance (QA) is proactive and prevention-focused, ensuring quality before the product is delivered, while quality control (QC) is reactive and detection-focused, inspecting and testing after production (ASQ Six Sigma). Too many QMSs are built around QC—final inspection, rejection rates, and rework—when they should be built around QA—process design, training, and preventive maintenance.

Auditing is part of QA (ASQ QA vs QC), but if your audits are just checking for conformity to procedures, you're doing it wrong. A good audit should uncover weaknesses in the process, not just nonconformities in the output. It should be a diagnostic tool, not a police patrol.

Why the New Revision Is a Wake-Up Call

The upcoming ISO 9001:2026 revision is a perfect opportunity to reassess. The new revision adds requirements for quality culture and ethical behavior, more clearly separates risks and opportunities, and strengthens management of change (ANSI Blog). It's not a complete overhaul—the core principles remain intact—but it's pushing us toward a more dynamic, risk-aware approach.

If your current system is static, the 2026 revision will be uncomfortable. That's a good thing. It's forcing us to ask: are we really managing quality, or are we just documenting it?

The Counterargument: Certification Drives Compliance

Some will argue that certification is a necessary evil—that without the external audit, nothing would get done. There's a kernel of truth there. The certification audit provides an external check, and the discipline of the audit cycle can keep people honest.

But that's a low bar. If your QMS exists only to pass audits, you're missing the point. The audit is not the goal; it's a checkpoint. The real goal is to build a system that prevents defects, reduces waste, and improves customer satisfaction. If you're only in it for the certificate, you're paying for a piece of paper that doesn't reflect your actual quality.

Comparison: Certification vs. Capability

ApproachFocusPrimary ActivityOutcome
Certification-drivenCompliancePreparing for audits, documenting proceduresCertificate on the wall, but stagnant processes
Capability-drivenImprovementUsing PDCA, risk-based thinking, employee engagementReduced defects, lower cost of quality, satisfied customers

The cost of quality framework helps here. Prevention costs—training, process design—are investments. Appraisal costs—inspection, testing—are necessary but don't add value. And the cost of poor quality—internal and external failures—is what we're trying to eliminate (ASQ Cost of Quality). A certification-driven approach inflates appraisal costs and accepts COPQ. A capability-driven approach minimizes both.

What I'd Actually Do

Here's my concrete advice: if you're certified, don't just update your manual for 2026. Use the revision as an excuse to conduct a deep, honest self-assessment. Map your key processes, identify where you're relying on detection rather than prevention, and invest in training your people on the seven quality management principles (ASQ). If you're not certified, don't rush to get the certificate. First, build a system that works—one that uses the PDCA cycle, involves your people, and is focused on customer satisfaction. Then, when you're ready, use the certification as a confirmation, not a goal.

And for those who say, 'But we need the certificate to bid on contracts,' I'll concede that's a real constraint. But the certificate is a ticket to the game, not the game itself. A QMS that actually improves quality will pay for itself many times over through reduced rework, fewer returns, and more repeat customers.

We have over a million certificates in the world. How many of those organizations are truly excellent? The ones that are excellent are the ones that see ISO 9001 for what it is: a framework for continuous improvement, not a trophy.

Sources

  • ASQ - https://asq.org/quality-resources/iso-9001
  • ANSI Blog - https://blog.ansi.org/ansi/iso-9001-2026-qms-revision-updates/
  • ISO Survey 2022 (AAA) - https://aaa-accreditation.org/iso-survey-results-of-certifications-to-management-system-standards/
  • ASQ (Six Sigma) - https://asq.org/quality-resources/six-sigma
  • ASQ (Cost of Quality) - https://asq.org/quality-resources/cost-of-quality
  • ASQ (QA vs QC) - https://asq.org/quality-resources/quality-assurance-vs-control

Share this article:

Comments (0)

No comments yet. Be the first to comment!