Skip to main content
Continuous Improvement

Your ISO 9001 Certificate Won't Improve Anything

Most quality teams treat certification as the finish line. That's backwards. Here's how to build a PDCA loop that actually changes how work gets done.

The most common mistake in quality management is treating the certificate as the goal. You pass the audit, you frame the certificate, you move on. Nothing changes on the floor. The standard itself warns against this: ISO 9001 is built on the Plan-Do-Check-Act cycle, a process approach, and risk-based thinking (ASQ). The certificate is just evidence that a system exists. It says nothing about whether that system improves anything.

We see this constantly. A company gets certified, then treats every subsequent audit as a re-certification exercise. Documents get updated. Records get signed. The same nonconformances reappear year after year. That's not a quality management system. That's a paperwork factory.

Imagine you run quality at a mid-sized medical device manufacturer. You've held ISO 13485 certification for years, and now the FDA's Quality Management System Regulation (QMSR) has made ISO 13485:2016 the core QMS requirement for most device makers, effective 2 February 2026 (NSF (FDA QMSR)). Your notified body audits you. Your FDA inspections reference the same standard. You're compliant on paper. But your internal scrap rate hasn't moved in 18 months, and your CAPA system is a graveyard of repeat issues.

What do you do? You stop treating the standard as a checklist and start running it as an improvement engine. Here's how we'd approach it.

Start with the gap between QA and QC

Most organizations conflate quality assurance and quality control. They are not the same thing, and the distinction matters for continuous improvement. Quality assurance is proactive and prevention-focused: it ensures quality before delivery through planning, documentation, and preventive tools. Quality control is reactive and detection-focused: it inspects and tests after production to identify defects (ASQ (Six Sigma)).

If your improvement efforts are all QC — more inspection, tighter sampling, additional testing — you're playing defense. You'll catch more defects, but you won't prevent them. The improvement work has to live in QA. That means auditing is part of the QA function, and inspection is the measurement activity that tells you whether your QA is working (ASQ (QA vs QC)).

In our medical device scenario, that means shifting resources from final inspection to process validation, design FMEA, and supplier development. The inspection data becomes an input to improvement, not the output.

Pick a framework, not a religion

There is no shortage of improvement methodologies. The question is which one fits your problem. Here's how we'd compare the main options for a manufacturer that already has a certified QMS:

Approach Best for Typical starting point Watch out for
PDCA Any process with a measurable output A single recurring problem Stopping after one cycle
Six Sigma (DMAIC) Variation reduction, defect elimination A process with known defect data Over-engineering simple fixes
Lean / 5S Waste, flow, workplace organization A messy or slow area Tools without culture change
FMEA Risk prioritization before failure New design or process Doing it once and filing it
Mistake proofing Preventing a specific known error A repeat defect Adding complexity instead of simplicity

In practice, we'd start with PDCA because it's the engine underneath everything else. Six Sigma, lean, and the rest are specialized tools you pull in when PDCA tells you what kind of problem you have.

Run PDCA like you mean it

The PDCA cycle is a four-step model: Plan (recognize an opportunity and plan a change), Do (test the change), Check (review the test and analyze the results), and Act (take action based on what was learned) (ASQ (PDCA)). That sounds simple. It is. It's also routinely done badly.

Most teams skip the Check step. They plan, they do, they declare victory, and they move on. But the cycle is supposed to repeat again and again, like a circle with no end. That repetition is where improvement actually happens.

There's also a naming issue worth clearing up. The cycle is often called the Deming cycle, but Deming never used the phrase 'plan-do-check-act' in his lectures. He introduced Walter Shewhart's methods to the Japanese, and the cycle is more accurately called the Shewhart cycle or the Plan-Do-Study-Act (PDSA) cycle (ASQ Quality Progress (Deming)). We prefer PDSA because 'study' implies more than checking a box. It implies learning.

For our device manufacturer, a PDSA loop on a recurring assembly defect might look like this: Plan a change to the fixture that's causing misalignment. Do a two-week trial on one line. Study the results — did defects drop, and did new ones appear? Act by standardizing the fixture change, then start the next cycle on the next-biggest defect.

Use the tools you already have

You don't need a new software platform to improve. You need to use the basic tools correctly. The seven QC tools — cause-and-effect diagram, check sheet, control chart, histogram, Pareto chart, scatter diagram, and stratification — were assembled by Kaoru Ishikawa in 1974 and remain the foundation of process monitoring (ASQ (SPC)).

Control charts deserve special attention. They distinguish between common cause variation, which is intrinsic to the process, and special cause variation, which comes from external sources and indicates the process is out of statistical control (ASQ (SPC)). If you're reacting to common cause variation as if it were special, you're tampering. You'll make things worse.

For detecting smaller shifts, CUSUM and EWMA charts are more sensitive than standard control charts. CUSUM plots cumulative deviations from target; EWMA weights recent data more heavily. Both are useful when you're trying to catch a slow drift before it becomes a failure.

Prevent the defect, don't just find it

Mistake proofing — poka-yoke — is the use of any device or method that either makes an error impossible or makes it immediately obvious once it occurs. The goal is zero defects through prevention or automatic detection (ASQ (Mistake Proofing)).

There are three inspection methods: successive inspection, where the next worker checks the previous step; self-inspection, where workers check their own work immediately; and source inspection, where conditions are checked before the step, often automatically preventing the process from proceeding until conditions are right. Source inspection is the strongest because it stops the error before value is added.

We'd prioritize mistake proofing for any defect that has appeared more than twice. If a defect keeps coming back, inspection isn't the answer. The process needs to be redesigned so the error can't happen.

Measure the cost of poor quality

Improvement needs a business case. Cost of quality gives you one. It categorizes spending into prevention costs, appraisal costs, and the cost of poor quality, which includes internal failure costs (defects found before the customer receives the product) and external failure costs (defects found after) (ASQ (Cost of Quality)).

Most organizations underinvest in prevention and overinvest in appraisal and failure. If your COQ data shows that, you have your improvement priority. Every dollar moved from failure to prevention is a dollar that shows up in margin.

For our device manufacturer, tracking COQ by product line would reveal which line is bleeding. That's where the next PDSA cycle goes.

Audit for improvement, not compliance

Auditing is part of the QA function, and it should be a source of improvement intelligence, not just a conformity check. The 2026 revision of ISO 19011, the guidelines for auditing management systems, was described by the Chartered Quality Institute as 'evolutionary not revolutionary' (CQI (ISO 19011:2026)). But two changes matter for continuous improvement.

First, the standard expands guidance on remote auditing methods and virtual locations, which means you can audit more frequently without travel costs. Second, the independence principle was revised: the old text said internal auditors should be independent of the function being audited 'if practicable,' and that's been replaced with guidance that when independence isn't possible, every effort should be made to remove bias and encourage objectivity.

In practice, that means your internal audit program can be more flexible and more frequent. Use that to feed PDSA, not to generate more paperwork.

What I'd actually do

If I were running quality at that medical device manufacturer, here's the plan. First, I'd pull 12 months of nonconformance and CAPA data and sort it by defect type. I'd pick the top three by frequency and cost. Second, I'd charter one PDSA cycle per defect, with a named owner and a 90-day window. Third, I'd require that every cycle end with either a mistake-proofing change or a control chart that proves the fix holds. Fourth, I'd report COQ quarterly to the leadership team, with a target of shifting 10% of spend from failure to prevention each year. Fifth, I'd retrain the internal audit team on the ISO 19011:2026 changes and double the audit frequency using remote methods.

None of this requires a new standard. ISO 9001:2015 already gives you the framework. The 2026 revision, expected in September 2026, adds quality culture and ethical behavior, but the core principles remain intact (ANSI Blog (ISO 9001:2026)). You don't need to wait for it. You need to run the cycle you already have.

The certificate is not the point. The improvement is the point. Everything else is just evidence.

Sources

  • ASQ - https://asq.org/quality-resources/iso-9001
  • ASQ (PDCA) - https://asq.org/quality-resources/pdca-cycle
  • ASQ (Cost of Quality) - https://asq.org/quality-resources/cost-of-quality
  • ASQ (Mistake Proofing) - https://asq.org/quality-resources/mistake-proofing
  • NSF (FDA QMSR) - https://www.nsf.org/life-science-regulatory-news/fda-qmsr-what-changed-and-why-it-matters
  • CQI (ISO 19011:2026) - https://www.quality.org/article/revision-iso-19011-what-you-need-know

Share this article:

Comments (0)

No comments yet. Be the first to comment!